library · field guide

Stop sharing passwords on sticky notes.

One shared login on the potting-shed terminal feels harmless — until a departed worker still knows it, an inspector asks who changed a price, or a temp deletes a batch nobody can trace. Access control is how a growing business stays accountable to itself.

the real problem

A shared login is a shared blind spot.

When everyone signs in as the same user, the system can tell you that something happened — never who did it, and never whether they should have been able to. Both answers matter more as a nursery grows.

why it drifts

How the sticky note ends up on the monitor.

Nobody sets out to run a nursery on one shared password. It creeps in. A single account is set up on the shop-floor till "just to get going." A seasonal picker needs to log a count, so someone reads the password out across the bench. A manager leaves, and their login keeps working because changing it would mean telling six people a new one. Convenience wins, one small decision at a time, until the password lives on a sticky note by the screen and everybody knows it.

The cost stays invisible right up until the moment it isn't. A price is changed and no one can say by whom. A batch is written off and the record shows only "the shared user." A worker who left in spring can still reach your customer list in autumn. None of these is a disaster on its own, but each is the kind of gap that turns a routine question into an uncomfortable one.

What helps is a system where the easy way to sign in is also the accountable one: each person is themselves, holds exactly the access their job needs, and can be switched off the day they leave.

Grant the job, not the person.

roles, not individuals

Grant the job, not the person.

Build access around roles: named bundles of permissions like Account Manager, Finance, Logistics, Production or Propagation Manager. A permission is a single, specific right: view customers, transmit an invoice, manage settings. A role gathers the rights a job actually needs, and a person is simply given one or more roles.

That indirection is the whole point. Rather than deciding per worker whether they may see supplier prices, you decide what a Finance person does, once, and every Finance hire inherits it. When a job changes, you adjust the role, not fifteen individual accounts. The propagation lead who moves to sales drops one role and gains another, and their access follows the move exactly.

Fast enough that nobody cheats it.

built for the bench

Fast enough that nobody cheats it.

Security that slows the shop floor gets bypassed, so signing in as yourself has to be faster than sharing a login ever was. A modern system should offer a member of staff three ways to sign in: email and password, an RFID smartcard they simply tap, or a passkey (a fingerprint, face unlock or hardware key with no password to type).

On a busy dispatch bench or a Saturday till, the tap-to-sign-in card is the difference between "everyone uses the shared account" and "everyone is themselves." The password never goes away; it stays as the durable way to recover an account. But for the hundredth login of the day, a card tap means the accountable path is also the quickest one.

the leaver problem

Offboarding should take one click.

The riskiest account is the one belonging to someone who no longer works for you. When access is personal, closing it is a single clean act instead of a scramble to remember every shared credential they ever knew.

When a worker leaves you suspend them rather than delete them. The account stops working immediately, but everything they ever did stays attached to their name in the record. History is preserved; access ends. And because a suspended account should never cost you anything to keep, there is no financial reason to leave a former worker able to log in.

The same discipline runs the other way. Sensitive actions should carry their own guardrails: editing another user's email address, say, ought to be its own permission held by admins alone, with every such change written to an activity log. The principle is consistent: who can do what is explicit, and what they did is recorded, so the answer to "who changed this?" is always already written down.

Not everyone needs to see the margins.

least privilege

Not everyone needs to see the margins.

Commercial data is worth guarding, and most workers neither need nor want the whole system. A picker logging a count has no reason to see supplier cost prices; a seasonal retail hand has no reason to reach the customer database. Giving each role only what the job requires is simply cleaner, and it keeps the sensitive corners of the business narrow by default.

When permissions are grouped by area (customers, invoices, settings and so on) you can grant a whole area at once or open a single action within it. The result is access that maps to how your nursery actually divides its work, rather than an all-or-nothing choice between "locked out" and "sees everything."

Every action has a name on it.

accountability, evidenced

Every action has a name on it.

Once each person signs in as themselves, the system stops recording that something happened and starts recording who did it. A price change, a stock write-off, a transmitted invoice — each carries the identity of the person behind it, because there is no longer an anonymous shared account to hide in.

This is where access control stops being a compliance chore. When an inspector follows a plant passport, when a customer queries a figure, or when you simply need to understand a change from last month, the trail is already there: attributed, dated and intact.

atlas core

How Atlas Core handles roles and permissions

Everything above is general practice for any grower. Here is how Atlas Core puts it to work on the nursery floor:

  • Role-based access out of the box. Named roles (Account Manager, Finance, Production, Propagation Manager) bundle the exact permissions a nursery job needs, so you assign the job once instead of wiring up rights per worker.
  • Three fast ways to sign in as yourself. Email and password, a tap-to-login RFID smartcard for the dispatch bench and Saturday till, and passkeys (fingerprint, face or hardware key), so the accountable path is also the quickest and nobody falls back to a shared account.
  • One-click offboarding, suspend-not-delete. A leaver's account stops working instantly while their full history stays attached to their name, and because only active users count toward your seats, a suspended account costs nothing.
  • Least-privilege by area. Cost prices, customer data and settings are grouped so you can grant a whole area or a single action, keeping margins and commercial data visible only to the roles that genuinely need them.
  • A per-user activity trail on every sensitive action. Price changes, stock write-offs, transmitted invoices and even editing another user's email (an admin-only permission) are attributed, dated and logged, so "who changed this?" is answered before an inspector or customer ever asks.

Read further

In praise of boring technology Tech brief · 2026

In praise of boring technology

The software that runs your nursery will still be running it in ten years - exactly the wrong place to chase the newest tool. What 'boring' technology buys: fewer moving parts, fewer 3am surprises, and excitement kept for the plants.

6 min read · Jul 2026 Read →

See how Atlas Core keeps access accountable.

Book a walkthrough and see roles, tap-card and passkey logins, clean offboarding and a full activity trail working on your own shop floor. We will help you set up access that fits exactly how your nursery divides its work.