Skip to content
Module 06 · Access

The right screen for the job.

A technician on a ladder doesn't need the finance module. Portal roles get a curated shell — focused navigation, their own records, exactly their work. Underneath, the same permission model runs as if the whole app were one keystroke away.

crest / portal / home
snapshot
MR

M. Reyes

IT Technician

My visits

own records only

  • SHS network drop — draft

    Draft

    SPCM · Matina, Davao

  • Term-1 maintenance — submitted

    Submitted

    Northgate Christian School

Technicians see their own visits, tasks, and expenses — a focused shell, with permissions still enforced server-side.

A portal is a role, narrowed — not a separate product

Three portals, drawn from real work.

Each portal exists because that job exists: maintaining deployments, coordinating schools, answering schools.

IT Technician

The person in the ceiling with the crimper.

  • +Technical visit drafts and submissions
  • +Inventory, stock movements, deployments
  • +Client sites derived from deployed equipment
  • +Own expenses and assigned tasks
  • +School-scoped documents

Boundary

Sees only their own visits unless granted visits.manage

Sales & Marketing

The field coordinator between schools and the office.

  • +Client schools and school documents
  • +Notion task workspace
  • +Google Drive school folders
  • +Sales pipeline
  • +Own expenses with budget context

Boundary

Cannot approve their own fund requests or reconcile budgets

Customer Care

The voice schools call first.

  • +Shared client-school profiles
  • +Lifecycle and service operations
  • +Contacts, population, training, support work
  • +Sanitized school activity

Boundary

No Essentiel pricing or school finance by default

And one management shell for everyone else.

Eight roles run the main application, each with a permission grant set — from Owner down to Viewer. Owners automatically receive every future permission; the last active Owner can never be removed.

OwnerAdministratorSecretaryFinanceAccount ManagerImplementation ManagerViewer

Self-service is bounded by ownership: portal users update only their own tasks, submit only their own expenses, and see only their own activity. Every boundary is checked server-side — the narrow navigation is a convenience, never the security. Next: reporting and the audit trail.

See Crest on your own portfolio.

A working session with your numbers: schools, subscriptions, receivables. We'll set up a workspace and walk your lifecycle end to end.

Invitation-only · Onboarding guided by the team that built it