India Audit Lens
Configure role permissions and user overrides
Maintain the role-permission matrix for consistent access, then use a time-bounded user override only for a justified exception. The Managing Partner remains protected with full access as stated on the page.
By India Audit Lens product team · Updated 2026-07-17
Review the matrix
Navigate to Settings → People → Roles & Permissions. Read the page description and protected-role notice. For each resource/action row, review the enabled permission across roles. Compare the matrix with the firm's approved responsibility and segregation-of-duties model. Note which users currently hold each role before reducing access needed for live deadlines.
Change role permissions
Select or clear only the intended cells. Changed cells are highlighted and the page counts pending changes. Review every changed role/resource combination. Click Save changes. Wait for the permission-updated success message. Open the Change log and verify actor, timestamp, role, permission, and change. Test with a synthetic/non-privileged user where possible; do not validate only with an admin account.
Use Reset before saving to discard the current unsaved cell changes. It is not a reset of all firm permissions to system defaults.
Add a user-specific override
Open Settings → People → Team. Click Permissions beside the intended member. Review Effective Permissions to distinguish role-derived access from overrides. Open Permission Overrides and click the add action. Select Permission. Choose the grant/revoke Action. Enter a specific Reason. Enter Expires At for temporary access; avoid permanent overrides unless formally approved. Save and wait for Permission override saved. Recheck Effective Permissions and test the actual route/action.
Remove or expire an override
Confirm the business need has ended and no dependent work must first be reassigned. Remove the exact override and wait for Override removed. Recheck effective access and the audit/change history. If the permission is broadly required, update the appropriate role instead of repeatedly creating individual exceptions.
Expected result
Users receive predictable access from their role, every exceptional grant/revocation has a reason and appropriate expiry, protected roles remain intact, and changes appear in the audit log.