Setup checklist: start with the minimum role
List what each person must see and do to complete their responsibility. A producer may need the brief and working files without needing billing administration. A client’s finance contact may need an invoice without participating in creative review. ManyRequests documents separate role controls. Use those controls deliberately, but verify the actual configuration rather than assuming the default role name precisely matches the access your agency intends.
Test with two fictional clients
Create an approved non-sensitive test arrangement with separate organizations and distinct sample files. Check the ordinary client view, team view and administrative view. Record which organization and identity performed each observation. Merely hiding a link in navigation is not evidence that another client’s records are inaccessible. If a boundary cannot be verified using supported tools, leave that requirement unresolved and avoid loading confidential work into the configuration.
Include changes and departures
A contractor leaving a project should not leave an orphaned production task or indefinite access. Decide who reassigns the work and who removes access through the supported process. Keep the original job and approval history intact. Do not delete a client record just to make a dashboard look tidy without first understanding the data and contractual consequences. Permission management is a lifecycle responsibility, not a one-time setup checkbox.
Keep evidence without collecting secrets
Record the role, permitted action, observed result and date. Do not copy passwords or access tokens into the acceptance sheet. For sensitive projects, obtain the appropriate professional assessment rather than treating this checklist as a security certification. Recheck relevant boundaries when roles or integrations change. A useful access policy is small enough to maintain and explicit enough that the next administrator can understand why each person has the permissions they do.
Sources used for this page
These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.
- ManyRequests admin, client and team permissions — Merchant documentation · help.manyrequests.com · Merchant-controlled · checked 2026-09-19
- ManyRequests security statements — not independent certification — Merchant documentation · manyrequests.com · Merchant-controlled · checked 2026-09-19