Custom fields on any object with real types, validation and an immediate place in the API. Permissions resolved by role, team and record, down to individual fields. An audit trail no administrator can edit. Documented REST with a token per integration and webhooks matching the interface's own events. Import and bulk edit that show a diff before committing. And a sandbox to break.
None of these is a plan tier. They behave the same on the smallest plan as on the largest.
Because evaluations are won on features and deployments are lost on administration. The pipeline demo goes well; the rollout stalls because margin is visible to everyone, the import wrote 400 blank owners, and the integration was built against a data model that does not match the product.
These are the parts nobody asks about in a trial and everybody lives with for years.
Permissions come from the reporting structure Nest already holds, so a reorganisation moving forty people takes effect the same afternoon rather than becoming a quarter-long access review. You can ask what one person can see and get an answer.
And because there is one data model, a custom field added this morning is in the API this morning, with its type, in the same response shape an existing integration is already reading.
It will not stop somebody with legitimate access from misusing it — that is what the audit trail is for, and the two are designed to be read together.
And it will not undo a committed import as a single action. Approving the diff beforehand is the safety mechanism; the audit trail then makes a correction possible, which is a different thing from a rollback button.
Decide field-level permissions before inviting managers rather than after. Margin and cost are the usual cases, and it is the one setting people notice immediately if it is wrong in either direction.
Use the sandbox for permission reworks specifically. A change that looks correct and quietly removes a team's access to renewals is much better discovered on a Tuesday in a copy than on a Monday in production.
Every product resolves access the same way, so offboarding someone in Nest removes their reach across Flow, Loop, Desk, Books and Growth in one action rather than six and a forgotten seventh. The API is the same API for all of them. Loop phases, Books invoices, Desk tickets and Nest personnel records are one surface with permissions resolved per token.
Permissions come from the reporting structure Nest already holds, so a reorganisation moving forty people takes effect the same afternoon rather than becoming a quarter-long access review. You can ask what one person can see and get an answer.
It will not stop somebody with legitimate access from misusing it — that is what the audit trail is for, and the two are designed to be read together.
Decide field-level permissions before inviting managers rather than after. Margin and cost are the usual cases, and it is the one setting people notice immediately if it is wrong in either direction.
Fourteen days, every module, no card. Or half an hour with someone who will run it on your own records and tell you where it does not help.