In the startup years, access lives in the owner’s head: who is trusted, who can see payroll, who can take the seal. Everyone “knows.” Once you have contractors, rotations, vendors and subsidiaries, “everyone knows” becomes three stories in the same week. When something breaks, nobody can prove what the rule was. People only blame who overstepped.
It will fail because verbal access does not expire with the role
Permissions fail in three common ways. First, seeing what you should not: sales opens someone else’s commission sheet; admin downloads every ID. Second, doing what you should not: an unauthorized person completes a seal or changes an approval end point. Third, not being able to do what you should: the only operator is on leave and the company stops. None of these is “bad staff quality.” The rule has no object—no role, no data scope, no reclaim at handover. How disputes and leaks drop once access is clear: How clear permissions cut disputes and leaks.
At scale, familiar faces fail before policy does
Twenty people can run on tacit knowledge. At eighty, tacit knowledge favors veterans, blocks new hires, and every exception goes to the owner. Why the headcount ladder forces a system: From 20 to 80 people, why management has to be systematized. If a manager leaves with only “you cover,” to-dos and access break together. Compare How to-dos and permissions survive when a manager leaves. Ship HR and attendance without turning approval access into rules, and the floor returns to hallway talk—see What happens if you only ship HR and attendance, and skip approvals.
A Feishu or DingTalk directory is not a permission model. Being in a group or opening a sheet is often wider than the role. A custom back office writes “who can approve a contract, who can see payroll, who can export clients” as configurable roles. When someone changes jobs, access changes with them. Why you need the system: Why companies need a management system. DaXi draws roles and data scope with you before any form, so hallway talk is not copied into a row of switches. Tell us who you most fear seeing what on the Management systems service page.
Temporary grants need an expiry date
The most dangerous verbal rule is not “we never had one.” It is “just this once” with no close. Borrowed accounts, seals taken off-site, assistants approving for someone—still open after that afternoon, default three months later. Write proxy, reassignment and off-site seals as dated grants that auto-reclaim. Then disputes have a cell to check—see How clear permissions cut disputes and leaks. If groups and subsidiaries still run on “someone at HQ knows them,” isolation and roll-up both idle. See Group and subsidiaries: isolate permissions, still report up. Treat exceptions as permission events, or hallway talk will tear again at the next transfer.