Platform How it works Who it's for Compliance Health Check Insights About Book a demo
Home / Insights / Compliance

Who should see which site?

Compliance · Access & structure · 3 min read · 4 August 2026

Every multi-site organisation eventually hits the same argument. Should a site manager see the whole estate, or only their own building? It gets treated as a permissions question. It isn’t. It’s a question about whether people will trust the system enough to put real information into it.

Too much access, and the register gets noisy

Give everyone everything and the register becomes a wall. A manager of one care home logs in, sees four hundred compliance items across eleven homes, and starts building their own filtered view — usually in a spreadsheet, usually on their own laptop. Within a month the shadow copy is the one they actually work from, and the system has quietly become a place they upload things to rather than a place they work.

Too little access, and the picture fragments

Lock it down too hard and the opposite happens. Nobody but head office can see across sites, so nobody local notices they’re an outlier. The regional pattern — three sites all behind on the same check, because the same contractor let all three down — is invisible to the only people close enough to act on it quickly.

Scope by responsibility, not by hierarchy

The arrangement that works in practice is simple to state: people see the sites they’re responsible for, and roll-ups above that. A site manager sees their site. A regional manager sees their region and the comparison across it. A group compliance lead sees everything. Nobody has to filter, and nobody is guessing at what they can’t see.

Two design points matter more than they sound. First, the filter should persist — if someone works across four of twelve sites, they should not re-select those four every morning, because a filter people have to reapply is a filter people abandon. Second, and more seriously: the scope must be enforced on the server, not just hidden in the interface. If a report or a spreadsheet export can return rows the screens wouldn’t show, you don’t have access control — you have a UI convention.

The structure underneath

Access only works if the shape of the organisation is modelled honestly. Most estates need three levels: the organisation, the property, and departments within a property. That last one gets skipped and shouldn’t. Substances under COSHH, local risks and much day-to-day maintenance belong to a kitchen, a workshop or a ward — not to a whole building. Without departments, those items pile up at site level and ownership blurs.

There’s also a category of people who belong to no site at all: head-office and group staff. A pure site filter can’t reach them, which is why they need to be reachable deliberately rather than being an accident of whoever holds unrestricted access.

The test

Here’s the practical check. Ask three people at different levels the same question about the same site, on the same morning, from the system. If the answers differ, the problem is almost never the data. It’s that they’re all looking at different subsets and none of them knows it.