Brilliance One Users

Know who they are. Control what they can do.

Manage users, identities, roles, permissions, security groups, profiles, account relationships, departments, module access, and operational responsibilities from one connected platform.

Brilliance One Users connects platform access with the employee, customer, vendor, contractor, partner, organization, or other real business relationship behind the login.

Identity • Roles • Permissions • Relationships • No Per-User Pricing
Brilliance One user identity roles permissions and access management software

Identity & Access

A login should understand the person and responsibility behind it.

Brilliance One connects authentication and access with the relationships, departments, roles, modules, responsibilities, and business workflows that explain why a user needs the system in the first place.

Identity

Who Is This Person?

Maintain the user account, profile, authentication context, contact information, and appropriate relationship with the organization.

Responsibility

Why Do They Need Access?

Connect users with employees, customers, vendors, contractors, partners, departments, teams, projects, locations, and other business responsibilities.

Access

What Can They Do?

Apply roles, permissions, security groups, module access, administrative controls, and other supported visibility rules according to responsibility.

Beyond Login Management

A user account explains access. The business relationship explains why.

User management becomes more useful when access is connected to the person, organization, employment relationship, customer account, vendor relationship, or operational role behind it.

  • Who is the user?
  • Are they an employee or external user?
  • Which organization do they represent?
  • Which department are they part of?
  • What role do they perform?
  • Which modules do they need?
  • Which records should they see?
  • Which actions may they perform?
  • Which administrative capabilities do they need?
  • When should that access change or end?

Identity + Business Context

Who you are and what you may do are related. They are not the same thing.

Brilliance One separates identity from authorization while allowing both to remain connected to the underlying business relationship.

That makes the user record part of the Business Operating System instead of simply a username with a collection of switches.

User Relationships

More than employee logins.

Different people can interact with the same business for very different reasons. Their access should reflect the relationship they actually have with the organization.

Employees Connect workforce identity with HR, scheduling, projects, time, training, permissions, technology assets, and other internal workflows.
Customers Provide supported customer or portal access associated with the appropriate CRM account and customer relationship.
Vendors Associate vendors and suppliers with appropriate records, documents, projects, financial activity, or portal access where enabled.
Contractors Give external workers access appropriate to their responsibilities without treating them as full internal administrators.
Partners Connect partner users with the accounts, collaboration, projects, referrals, or operational workflows they participate in.
Administrators Provide deeper security, configuration, user-management, integration, and platform responsibilities to authorized administrators.

Relationship-Aware Identity

Keep the login connected to who the person represents.

A platform identity can connect with the underlying customer, employee, vendor, contractor, supplier, partner, organization, department, or other relationship that gives the access business meaning.

  • Employee records
  • Customer accounts
  • Customer contacts
  • Vendor accounts
  • Supplier relationships
  • Contractor relationships
  • Partner organizations
  • Departments
  • Locations
  • Other supported relationships

Relationship Context

The login tells the system who signed in. The relationship explains what that means.

An employee may need internal operational access. A customer may need a portal. A vendor may need access to specific records. A contractor may participate in one project without seeing unrelated company information.

Linking identity with the real relationship helps Brilliance One keep access, communication, history, and responsibility understandable.

User vs. Employee

Employment identity and application identity are different.

Human Resources describes the employment relationship. Users controls access to Brilliance One. Connecting them allows both records to remain useful without forcing them to become the same thing.

Employee

Workforce Relationship

Represents employment status, department, manager, role, location, training, attendance, reviews, documents, responsibilities, and other workforce context.

User

Application Access

Represents authentication, roles, permissions, modules, security groups, administrative privileges, preferences, and the ability to use Brilliance One.

Roles

Define what common responsibility looks like.

Roles can group repeatable access patterns so users performing similar work do not require every permission to be configured independently.

  • Administrator roles
  • Manager roles
  • Employee roles
  • Department roles
  • Sales roles
  • Accounting roles
  • HR roles
  • Customer access roles
  • Vendor or partner roles
  • Custom organizational roles

Reusable Access

Configure the responsibility. Reuse the access pattern.

Role-based access can reduce repetitive administration when multiple users need similar module, action, data, and workflow permissions.

Individual exceptions can still be handled where the permission model supports more specific control.

Permissions

Control what each user can see and do.

Permissions provide more specific control over which modules, records, actions, tools, administrative functions, and sensitive workflows are available to an authenticated user.

Modules

Module Access

Control which supported Brilliance One modules and functional areas are available to a user or role.

Actions

Operational Permissions

Limit appropriate create, update, approval, administrative, financial, export, configuration, or other supported actions according to responsibility.

Data

Visibility Controls

Apply supported rules that help restrict sensitive customer, employee, financial, document, firearms, project, or other information to appropriate users.

Administration

Privileged Functions

Restrict security, settings, users, licensing, integrations, billing configuration, exports, and other higher-impact administrative capabilities.

Documents

Sensitive Files

Use supported document and module permissions to help keep appropriate files visible only to users who require them.

Operations

Responsibility-Based Access

Align supported permissions with the work users are expected to perform instead of giving every authenticated person the same level of access.

Least Necessary Access

Give people what they need. Not everything the platform can do.

A connected Business Operating System can contain customer, accounting, HR, project, document, POS, firearms, administrative, and other sensitive information. Access should reflect responsibility.

  • Sales users need sales access
  • Accounting users need financial access
  • HR users need workforce access
  • Project users need delivery access
  • Cashiers need appropriate POS access
  • FFL personnel need appropriate firearms access
  • Customers need customer-facing access
  • Vendors need limited external access where applicable
  • Administrators need privileged controls
  • Everyone does not need everything

Permission Strategy

Access should follow the job. Not the size of the software.

Adding more modules to Brilliance One should not mean every user automatically gains access to every new capability.

Roles, security groups, module permissions, and supported record-level controls help maintain separation as the platform expands.

Security Groups

Organize access around common responsibility.

Security groups can help administrators apply related access controls to collections of users whose responsibilities require similar treatment.

Department

Functional Access

Group users around sales, accounting, HR, operations, technology, customer service, or other organizational functions where appropriate.

Management

Supervisory Access

Provide additional visibility or administrative capability to users responsible for supervising a team or operational area.

Specialized

Sensitive Workflows

Use appropriate access groups around financial, HR, firearms, security, document, or other specialized information.

User Profiles

Give each user an appropriate identity inside the platform.

Profiles can provide the display, contact, organization, department, role, communication, and presentation information used across supported internal and external experiences.

Display Identity

Maintain supported name, title, role, and presentation information.

Contact Details

Associate appropriate email, phone, address, and other communication information.

Organization

Connect the user with the company, customer, vendor, partner, department, or team they represent.

Role Context

Represent the user's responsibilities and access within the platform.

Preferences

Maintain supported user-specific presentation, notification, or communication preferences.

History

Associate appropriate user activity with broader business workflows and operational records.

Role-Aware Experience

Show users the work that matters to them.

Supported dashboards, navigation, modules, and workspace experiences can reflect the user's permissions, responsibilities, relationship, branding, and available capabilities.

  • Role-aware dashboards
  • Module visibility
  • Relevant navigation
  • Operational responsibilities
  • Account context
  • Organization branding
  • Supported preferences
  • Permission-aware content

Focused Workspace

A cashier and an accountant should not need the same workspace.

The platform can contain many capabilities while individual users remain focused on the modules and information relevant to their responsibilities.

Broad platform capability does not have to create broad user complexity.

Access Lifecycle

Access should change when responsibility changes.

User access is not a one-time decision. Roles, departments, assignments, employment, customer relationships, projects, and responsibilities can all change over time.

1

Provision

Create the identity, connect the appropriate relationship, assign roles, establish permissions, enable required modules, and provide the initial workspace.

2

Maintain

Adjust roles, permissions, modules, departments, teams, relationships, administrative privileges, and responsibilities as the person's work changes.

3

Restrict or Disable

Remove, restrict, or disable access when the person no longer requires the same privileges while preserving appropriate historical business records.

User Onboarding

Give new users the right access from the beginning.

User setup can connect identity, relationship, role, department, permissions, modules, security requirements, and workspace responsibilities instead of treating account creation as an isolated IT task.

  • Create user identity
  • Connect employee or account relationship
  • Assign role
  • Assign permissions
  • Assign security groups
  • Enable modules
  • Configure authentication requirements
  • Set appropriate profile information
  • Establish workspace access
  • Review administrative privileges

Consistent Provisioning

New access should begin with the job.

Roles and reusable permission structures can reduce repetitive setup while still allowing administrators to review access appropriate to the individual.

The objective is consistent access without blindly cloning privileges that the new user does not need.

User Offboarding

Remove the access. Preserve the history.

When an employee, contractor, partner, vendor, or other user no longer requires access, the platform identity can be restricted or disabled without erasing the legitimate business history associated with that person.

  • Disable authentication
  • Restrict modules
  • Remove privileged access
  • Review active responsibilities
  • Review project assignments
  • Review scheduled activity
  • Review technology assets
  • Review customer ownership
  • Preserve operational history
  • Maintain appropriate audit context

Identity History

The person may leave. Their legitimate business history should not disappear.

Project work, customer communication, approvals, documents, sales activity, accounting actions, and other historical records can still require attribution after the user's access ends.

Access lifecycle and business-history lifecycle are related, but they are not identical.

Authentication

Verify identity before evaluating access.

Brilliance One Users relies on the shared Security foundation for credential protection, authentication, account controls, sessions, and other supported identity protections.

Credentials

Password Protection

Use Argon2id password hashing with unique salts and additional application-level protection to help protect stored credential material.

Multi-Factor

Additional Verification

Where enabled, multi-factor authentication adds another verification requirement beyond the primary account credential.

Sessions

Ongoing Access Controls

Session validation, expiration, account controls, authorization checks, and other supported protections help govern ongoing authenticated access.

Authentication + Authorization

Authentication answers who. Authorization answers what.

Successfully proving identity should not automatically provide unrestricted access to every function and record in the platform.

  • Authentication establishes identity
  • Roles establish common responsibility
  • Permissions govern capabilities
  • Security groups organize access
  • Modules define available functional areas
  • Record rules limit supported visibility
  • Administrative privileges remain restricted
  • Sensitive actions require appropriate authorization

Identity Is Not Permission

Knowing who signed in does not answer whether they should see payroll.

Authentication and authorization solve different security problems.

Brilliance One keeps both connected so the platform can know who the user is while separately evaluating what that user should be permitted to access.

Users + Human Resources

Connect workforce responsibility with platform access.

When the user is also an employee, Brilliance One can connect application identity with the workforce record describing department, role, manager, location, training, availability, and other employee context.

Employment

Workforce Identity

Keep employment context in HR while connecting the appropriate employee to the user identity responsible for platform access.

Responsibility

Roles & Departments

Use organizational role and department context when administrators evaluate which platform capabilities the employee requires.

Lifecycle

Onboarding & Offboarding

Coordinate access decisions with appropriate workforce changes while maintaining separate historical records for employment and system activity.

Users + Technology

Access is one part of getting an employee ready to work.

Employee onboarding and offboarding can involve application access as well as laptops, phones, vehicles, tools, equipment, software, and other technology resources.

  • User account
  • Security access
  • Laptop assignment
  • Mobile device assignment
  • Vehicle assignment
  • Tool or equipment assignment
  • Software responsibility
  • Asset return context

Digital + Physical Access

Disabling a login is not always the entire offboarding process.

Technology can identify equipment assigned to the employee while Users governs the application identity and Human Resources preserves the employment context.

That is the advantage of connecting workforce, access, and asset operations inside the same system.

Users + Projects

Identity provides accountability around the work.

Project activity can retain appropriate user context around ownership, tasks, approvals, communication, documents, updates, and other delivery activity.

Ownership

Who Owns the Work?

Associate projects, tasks, milestones, or other supported responsibilities with the users or employees responsible for them.

Access

Who Should See It?

Use applicable permissions and project visibility to help restrict information according to responsibility.

History

Who Did What?

Preserve available user context around supported project activity and operational changes.

Users + Scheduling

Connect the person to the appointments they are responsible for.

Where configured, user and employee context can participate in scheduling workflows involving availability, appointments, service responsibility, teams, and operational calendars.

  • Employee relationship
  • User identity
  • Availability
  • Appointment responsibility
  • Service assignment
  • Schedule visibility
  • Team context
  • Customer context

Person + Schedule

A calendar entry is more useful when the system knows who is responsible for it.

Users provides identity and access while Human Resources and Scheduling provide the workforce and calendar context around the person performing the work.

External Users

External access should not become internal access.

Customers, vendors, contractors, partners, and other external users may need access to selected information without gaining visibility into unrelated internal operations.

Customers

Customer Access

Provide supported portal or customer-facing access connected to the appropriate CRM relationship and authorized information.

Vendors

Supplier Access

Provide appropriate vendor or supplier access where workflows require external participation.

Contractors

Limited Work Access

Give contractors access to supported projects, records, documents, or workflows required for their work without exposing unrelated areas.

Users + Security

Identity is the beginning of access control.

Brilliance One applies the shared Security foundation around authentication, authorization, credentials, sessions, administrative access, permissions, logging, and sensitive workflows.

  • Credential protection
  • Authentication
  • Multi-factor authentication where enabled
  • Roles
  • Permissions
  • Security groups
  • Module access
  • Administrative controls
  • Session controls
  • Audit and operational history

Access Foundation

Security starts with knowing which identity is making the request.

Users establishes identity context. Security applies the controls responsible for verifying that identity and determining whether the requested action should be allowed.

User & Access History

Important access changes should leave useful context.

Available user, permission, security, administrative, and operational history can help organizations understand important access changes and activity over time.

User Status

Maintain appropriate information around active, restricted, disabled, or other configured user states.

Role Changes

Preserve available context when a user's organizational or access role changes.

Permission Changes

Maintain available administrative information around significant access changes.

Administrative Activity

Record supported higher-impact user and access-management actions for authorized review.

Authentication Activity

Use supported authentication and security history when investigating access concerns.

Operational Attribution

Keep available user context around important business activity performed throughout the platform.

Access Governance

Access should be reviewed instead of becoming permanent by default.

People change jobs. Employees leave. Contractors finish projects. Vendors change. Customers close accounts. Administrative responsibility moves between people.

  • Review active users
  • Review privileged users
  • Review role assignments
  • Review security groups
  • Review module access
  • Review administrative permissions
  • Review department changes
  • Review employment changes
  • Review external-user access
  • Disable unnecessary accounts

Access Is Temporary

Responsibility changes. Permissions should be able to change with it.

Brilliance One provides identity and access controls, while the organization remains responsible for determining which users should have which privileges.

Periodic access reviews help keep old responsibilities from becoming permanent privileges.

No Per-User Platform Pricing

Add the people who need access. Not another seat invoice.

Brilliance One standard platform pricing is based on Core and the business modules the organization activates rather than charging another recurring platform subscription simply because another authorized user needs an account.

  • No per-user platform subscription
  • Employees can receive appropriate accounts
  • Managers can receive appropriate accounts
  • Administrators can receive appropriate accounts
  • External users can be supported where configured
  • Permissions still control access
  • Security still applies to every identity
  • Modules remain permission-aware

Pricing Philosophy

Charge for capability. Not every person who needs to use it.

The organization should be able to give the right employees appropriate access without evaluating whether every additional user is worth another recurring software seat.

No per-user pricing does not mean unrestricted access. Authentication, roles, permissions, security groups, and module controls still determine what each user can do.

Connected Identity

Identity participates throughout the operating system.

User identity and access context can participate across CRM, HR, Projects, Scheduling, Technology, Accounting, Communications, Courses, Security, Documents, POS, and other Brilliance One workflows.

Accounts

Relationship Identity

Connect user identity with customers, vendors, partners, suppliers, contractors, organizations, and other relationship records.

Human Resources

Workforce Identity

Connect employee records with appropriate user identities, roles, departments, permissions, and workspace responsibilities.

Projects

Work Responsibility

Use identity context for project ownership, task responsibility, updates, documents, approvals, and delivery activity.

Scheduling

Availability & Appointments

Associate appropriate users and employees with schedules, availability, appointments, services, and operational responsibility where configured.

Technology

Equipment & Assets

Connect employees and users with laptops, devices, vehicles, tools, equipment, software, and other supported operational assets.

Accounting

Financial Responsibility

Apply appropriate identity and access controls around financial information, approvals, payment activity, vendors, reporting, and administrative accounting actions.

Courses

Training Identity

Connect appropriate employee or user identity with course participation, training, completion, certification, and learning history.

Documents

File Access

Apply appropriate identity and permission context around business documents and sensitive supporting files.

Security

Authentication & Authorization

Use the shared security foundation for credential protection, sessions, permissions, security groups, administrative access, and security history.

Identity Platform Strategy

Modern platforms manage permissions. Brilliance connects permissions to operations.

Modern CRM and customer platforms already provide sophisticated user administration, teams, permission sets, module controls, assigned-record visibility, and granular permissions. Brilliance One extends identity and access into a broader combination of CRM, ERP, workforce, commerce, content, projects, assets, industry workflows, and other business operations.

Identify

Person + Relationship

Connect the user identity with the employee, customer, vendor, contractor, partner, department, or organization the person represents.

Authorize

Roles + Permissions

Apply the access required for the person's modules, records, actions, responsibilities, and administrative functions.

Operate

Business Responsibility

Use that identity across projects, schedules, HR, technology, documents, accounting, communications, training, commerce, and other operational workflows.

Identity Controls

Identity connects access, relationships, and accountability.

A useful identity system should establish who the user is, connect the user to the appropriate business relationship, limit access according to responsibility, and preserve useful history around significant activity.

Authentication

Verify Identity

Use protected credentials, multi-factor authentication where enabled, sessions, account controls, and other supported security measures.

Authorization

Limit Access

Apply roles, permissions, security groups, module access, record rules, and administrative controls according to responsibility.

Relationships

Connect the Person

Associate users with the employee, customer, vendor, supplier, contractor, partner, department, or organization behind the access.

Experience

Focus the Workspace

Use available modules, permissions, dashboards, navigation, branding, and preferences to keep the user experience appropriate to the person's responsibilities.

Lifecycle

Maintain Access

Provision, adjust, review, restrict, and disable user access as relationships and responsibilities change over time.

Accountability

Preserve Context

Maintain available identity and user context around supported business, administrative, and security activity.

Brilliance One Core

One shared foundation. Used throughout the platform.

Core provides the relationship, communication, automation, identity, security, configuration, and administrative capabilities that support the broader Brilliance One Business Operating System.

CRM & Relationships

Accounts

Manage customers, prospects, leads, organizations, contacts, vendors, suppliers, partners, and relationship history through one connected business record.

Explore Accounts

Locations

Addresses

Maintain billing, shipping, service, customer, employee, vendor, job-site, and operational locations as reusable records connected to the business activity that depends on them.

Explore Addresses

Email, SMS & Messaging

Communications

Connect email, SMS, MMS, campaigns, templates, lists, replies, delivery activity, and communication history with the customers and business records behind every conversation.

Explore Communications

Workflow Automation

Automations

Automate supported email, SMS, tagging, notifications, delays, follow-up, and repeatable processes so people can focus on decisions while software handles routine work.

Explore Automations

Identity & Access

Users

Manage identities, roles, permissions, security groups, profiles, account relationships, module access, authentication, and operational responsibilities across Brilliance One.

Explore Users

Platform Protection

Security

Protect business information with authentication, authorization, roles, permissions, security groups, encryption, session controls, logging, monitoring, and administrative safeguards.

Explore Security

Platform Configuration

Settings

Configure organization defaults, branding, permissions, communication providers, payment services, AI preferences, integrations, module behavior, and shared platform settings.

Explore Settings

Data Operations

Tools

Import, export, map, validate, review, migrate, clean, and maintain supported business information with administrative workflows designed for controlled data operations.

Explore Tools

Brilliance One Users

Know who they are. Control what they can do.

Connect employees, customers, vendors, contractors, partners, administrators, roles, permissions, security groups, profiles, modules, authentication, relationships, and operational responsibilities through the shared identity foundation of Brilliance One.

Brilliance One • Users • Identity • Roles • Permissions • Access