Because permissions are usually a per-user list maintained by hand. Somebody changes team, their old access is never removed, and after two years nobody can say who can see the margin.
Permissions determine what each person can see and change at three levels: the role they hold, the team they belong to, and the individual record — with field-level rules on top.
Access is derived from the personnel structure in Nest rather than kept as a second list. A change of team or manager takes effect immediately, and every rule is inspectable — you can ask what one person can see and get an answer.
A reorganisation moved 40 people across six teams. Because access derives from reporting lines, it followed the same afternoon, and the audit trail showed exactly what changed rather than requiring a review.
It will not stop somebody with legitimate access from misusing it. That is what the audit trail is for, and the two are designed to be read together.
Every product obeys the same rules: Desk tickets, Loop projects, Books invoices, dashboards, exports and the API all resolve access the same way, because they read one record model.
Yes. Margin and cost are the usual cases, visible to finance and not to everyone with the account.
Yes, per token. An integration cannot read what its user could not.
Closing their record in Nest removes access immediately, and their history stays on the records.
Fourteen days, every module, no card. Or half an hour with someone who will run it on your own records and tell you where it does not help.