library · field guide

The boss shouldn't be the superuser.

It feels wrong to tell the person who owns the place that the system says no. So the owner's login gets everything — and the widest, most irreversible buttons in the business end up with the one person who opens the software least.

authority and access

Having the final say is not the same as having every button.

One is about who decides. The other is about whose hand is on the mechanism at the moment it moves. In a small company the same person answers both questions, and nobody ever asks why.

how it happens

The first account ever created, never looked at again.

Small firms run on a kind of quiet democracy. Six or ten people, most of them doing two jobs, decisions made standing round a bench or over coffee — and the owner with the final say when the room can't agree. It works. It is one of the genuine advantages of being small.

Then the business buys a system. The owner is the one who sat through the demo, the one who signed, the one whose email set it up. Their account is created first, and it is given everything, because at that moment there is nobody else and no reason to think about it. Nobody decides this. It is a default that gets set on day one and never revisited.

And afterwards the owner goes back to doing what an owner actually does: customers, the season's planting, the bank manager, the thing that broke in tunnel four. The system becomes the tool other people use for eight hours a day. Two years on, the person holding the most power in the software is the person who opens it least — and the gap between those two facts widens every month, invisibly, until the day it costs something.

The widest buttons, in the least practised hands.

blast radius

The widest buttons, in the least practised hands.

A permission is not a rank. It is a capability with consequences attached, and the consequences are rarely visible from the button. Voiding an invoice that has already gone to the tax authority. Changing a VAT rule. Deleting a customer with open orders behind them. Merging two product records. Rewriting a price list that three channels read from. Reopening a stock period that has been closed and reported.

Every one of those is a single click and a confirmation box. The person who does it most weeks knows which are ordinary on a Tuesday afternoon and which need the bookkeeper in the room first. That knowledge is practice, and it decays fast when unused.

So the owner opens the system for the first time in three weeks, sees the same button with the same label, and has none of it. Not through carelessness. Through the entirely reasonable fact that they have been doing something else with their year.

And now everything queues at one desk.

the other half of it

And now everything queues at one desk.

The mirror image of an owner who can do everything is a team that can't do much. If only one account can approve the credit limit, correct the invoice, unlock the price or set up an account for the new seasonal hand, then that work only happens when that one person is free.

They are at a trade fair. They are in a lorry. They are, occasionally, on holiday. So one of two things happens, and both are worse than the problem they came from. Either the work stops and a customer waits, or the password gets read out across the bench, "just for this one thing."

Now the most powerful account in the business is being operated by whoever needed it that morning, and every record it touches carries the owner's name. The permission model that was meant to express trust has quietly destroyed the one thing permissions exist to protect: knowing who actually did it.

the distinction that fixes it

Own the keyring. Don't carry every key.

An owner's real prerogative is deciding who holds what, seeing everything, and being able to take any of it back tomorrow. None of that requires standing possession of every dangerous action in the business.

Pulled apart, what an owner genuinely needs from a system is a short list, and only one item on it is a power anybody could misuse.

See everything. Reading is not risk. Margins, the ledger, every order, the awkward numbers — an owner should be able to reach all of it without asking, because that is where an owner's judgement actually gets applied. No business was ever damaged by a boss who could read the reports.

Decide who holds what. Creating people, giving them a role, taking it away again the day it stops being appropriate. This is the real governance power, it belongs to ownership without argument, and it is usefully a permission in its own right, entirely separable from the operational verbs.

Be able to get in when it genuinely matters, by taking the access deliberately: for a stated reason, with a record, ideally with an expiry. An emergency route that has to be used is treated as an emergency. One that is simply always on becomes the way things are done.

And the small-company table loses nothing in this. When the room decides to write off the batch, the owner's authority sits in the decision; it does not require them to be the pair of hands that executes it. Nobody thinks the owner has lost control of the fleet because they don't personally drive the lorry.

Give the button to whoever uses it on a Tuesday.

who should hold it

Give the button to whoever uses it on a Tuesday.

Once you stop assigning access by rank, the right answer is usually obvious. The person who runs the stocktakes should hold the write-off. The bookkeeper should hold the credit note. The dispatch supervisor should hold the delivery override. In a firm of eight everybody is trusted; what differs is that daily use teaches you what a button does after you press it.

That also gives each of them something an owner cannot delegate any other way: ownership of a domain. The person holding the permission is the person who notices when the numbers look wrong, because they are the only one touching them.

The corollary is uncomfortable but worth saying out loud. If a permission has no regular user, it should probably not be switched on for anyone — and if only one person in the building holds it, you have swapped a risky account for a single point of failure. Every key needs a second, named holder.

The dangerous actions should say what they are about to do.

design for the mistake

The dangerous actions should say what they are about to do.

Some of this is the software's fault, and it is fair to expect better. A button marked Delete above a box asking Are you sure? has told the person nothing at all. Sure about what? Sure about the twelve open orders and the three unpaid invoices hanging off the record they are about to remove?

A system that expects occasional users spells out the consequence at the moment of the click, and prefers mechanisms that can be undone: cancel rather than delete, credit note rather than quietly edit, suspend rather than remove. Reversibility is the cheapest safety feature there is — the record stays, and a wrong decision costs an afternoon rather than a quarter.

Where an action genuinely cannot be undone, it deserves a second pair of eyes before it goes through. Not a policy on a wall. A second named person in the system itself.

atlas core

How Atlas Core keeps the owner in charge without the blast radius

Atlas Core has no magic owner account, and that is deliberate — there is nothing in the system that quietly bypasses the rules because of who you are:

  • Every role is a defined set of permissions, including the top one. Admin is a named bundle like Finance, Logistics, Production, Account Manager or Propagation Manager — a list you can see and shape, not a bypass. An owner takes the role that matches what they actually do.
  • Managing people is its own, double-locked permission. Creating or changing a user requires the user permissions and Manage Settings together, so "who holds what" can sit squarely with the owner while the operational verbs of voiding, deleting and writing off sit with the people doing that work every day.
  • Records carry the person behind them. Orders, production logs and goods-in decisions keep the name of who created and changed them, so "who did this?" is answered without anyone having to reconstruct it.
  • Suspended users are free, so nobody has a reason to share a login. A seasonal hand gets their own account; when the season ends the account is suspended, their history stays attached to their name, and it stops occupying a seat. Only active internal users count towards your licence.
  • Even our own emergency access is time-boxed. When Atlas support needs root on an instance it is a deliberate act — a stated reason, the instance name typed out in full, automatic expiry after a set number of hours, and a security log entry. We hold ourselves to the rule this article is arguing for: no standing superuser, anywhere.

Read further

A plant remembers a cold lorry Field guide · 2026

A plant remembers a cold lorry

Plants never complain on arrival. They look fine at the gate, then bronze, drop leaves and stall three weeks later on someone else's bench - and the claim comes back to you, long after the lorry has been forgotten.

8 min read · Aug 2026 Read →
Last year's plan, again Field guide · 2026

Last year's plan, again

Every nursery forecasts. The only question is whether it does so on purpose - because sowing the same number as last year is a prediction too, made silently, by nobody, and never checked afterwards.

8 min read · Aug 2026 Read →

Keep the final say. Lose the blast radius.

Roles, permission areas and clean user management — see how access would fit the way your business actually divides its work.