management

Permissions and Oversight: Firm-Wide Visibility Without Overreach

Permissions and Oversight: Firm-Wide Visibility Without Overreach

Written by

Shashank Gupta

GTM & Growth

Sharing links

LinkedIn
Twitter / X
Email
Copy URL

See what Advisory AI does with your real meetings

Last updated •

Summarize with AI

See what Advisory AI does with your real meetings

Get articles like this monthly

See what Advisory AI does with your real meetings

TL;DR: Firm-wide oversight does not require firm-wide access. A role-based permission model separates what supervisors can see from what they can change, so advisers keep control of their client files while supervisors get the compliance visibility Consumer Duty demands. Atlas enforces those permissions across meeting notes, suitability reports, and compliance checks without requiring separate configuration per capability. Colin checks every suitability report against FCA Consumer Duty and COBS requirements before it leaves the adviser's desk, providing pass/fail verdicts and specific remediation guidance so inconsistencies surface during drafting rather than at audit.

Consumer Duty expects you to monitor outcomes across your whole book, not just sample a few files and hope the rest hold up. The operational question is how to get that firm-wide view without reading every adviser's private client notes, and without triggering the adviser resistance that kills adoption of any oversight tool.

We built our permission model to answer that question. This playbook explains how role-based permissions work in UK financial advice firms, what the FCA expects from data access controls, and how our permission hierarchy delivers supervisor oversight in production across multi-practice firms.

Defining User Roles for Compliant Firm Visibility

Role-based access in advice software maps to the roles your firm already has: adviser, paraplanner, supervisor. Each role sees what it needs to do its job, nothing more. The core principle is that visibility and edit rights are separate: a supervisor can see that a file exists, that it passed or failed its compliance checks, and that it is on track, without being able to change a word of it.

This separation matters because Consumer Duty board reporting requires firms to evidence how they monitor outcomes, document information-sharing across the distribution chain, and maintain oversight of data quality, and a structured, role-based permission model is the cleanest way to demonstrate that governance is in place.

A well-configured permission model delivers three things at once:

  1. Adviser privacy: each adviser sees their own book and their own client data.

  2. Supervisor visibility: firm-wide oversight of compliance and workflow status.

  3. Paraplanner throughput: support teams reach the meetings they need across the firm by default, scoped down to specific advisers once Team Management is configured.

Managing Specific Adviser Permissions

An adviser-level permission is designed to cover the adviser's own book of business: their client records, meeting transcripts, draft suitability reports, and follow-up communications. Visibility into other advisers' client files is controlled by firm configuration.

This directly addresses the surveillance objection advisers raise about firm-wide tooling. The adviser authors and owns their work. Oversight sits above it as a checking layer, not inside it as an editor.

Defining Supervisor Access Rights

Supervisor access is designed to give firm-wide visibility into documentation quality, compliance check results, and workflow status. The distinction is between "see the file" and "change the file," and it is the difference between oversight and overreach.

In practice, a supervisor using Atlas can ask a firm-wide question in plain English and get a cited answer scoped to their permission level. They see the answer the permission model allows, and edit rights stay with the adviser who owns the client relationship.

Managing Cross-Firm Access Rights

Multi-practice firms and consolidators need permissions that scope across practice groups, offices, or acquired firms. Cross-firm access in AdvisoryAI is configurable per group, not all-or-nothing, supporting oversight structures that align with how consolidators and networks organise their adviser teams.

Because Evie, Emma, and Colin are capabilities within Atlas, permission scoping applies once across the whole platform rather than being reconfigured per tool. For firms deploying across multiple adviser teams, we configure bespoke templates per firm at scale, preserving established document formats while enabling firm-wide oversight capability.

The Risks of Siloed Adviser Data

Siloed data is a compliance and operational risk, not a privacy feature. When advisers hold client information in private systems, supervisors cannot spot inconsistent documentation, and paraplanners cannot start work until the adviser shares notes. That is the sequential bottleneck: every person downstream waits for the person before them to finish, like a queue at a single checkout.

The cost compounds. Research cited in our From Paperwork to Peoplework whitepaper found that 43.3% of UK advisers report paperwork reducing the time they devote to advice itself, and 71.9% of firms spend between one and seven hours producing a single suitability report. When structured meeting notes reach the whole team within minutes of the meeting ending rather than days later, that bottleneck dissolves. The wider capacity argument is set out in our piece on why the advice gap is an operations problem, not a marketing one.

Managing Private Client Access Rights

Role-based permissions let firms configure who sees client files, and supervisors get the oversight they need through compliance outputs and workflow status. This is the model that lets firms move from spot-checking a sample of files to reviewing every case before submission, because the checking layer reads everything so the supervisor does not have to.

Protecting Data in Advice Workflows

We protect data as it moves through the workflow. Meeting notes generated by Evie are visible to the adviser first, then shared with paraplanners and support teams according to the configured roles. Data access is controlled by the permission model, as our privacy policy and terms of use set out.

How Permissions Protect Client Privacy

Restricting file access to authorised personnel is part of evidencing good outcomes under Consumer Duty, not just a security feature. A least-privilege permission model, backed by full document version history, is the cleanest way to evidence compliance, and our AI Framework for Advice Firms sets out how we govern data access, human review, and source traceability across the platform.

Monitoring Firm Performance While Protecting Privacy

Supervisors monitor firm-wide performance through compliance check results and workflow status rather than by reading every file. This is what good supervisor oversight in an advice firm looks like: the compliance net catches gaps, and the supervisor reviews the catch.

Consistency is what makes oversight possible without deep file access. If every adviser's output follows the same structure and passes the same checks, a supervisor can compare like with like from the results alone.

Ensuring Uniformity Across Advice Files

Standardised templates produce uniform advice files across advisers. Emma builds reports directly from your firm's existing bespoke templates, preserving established document structures while generating consistent output from every adviser, as our suitability report workflow shows. Uniformity is a permission-adjacent benefit: consistent structure makes oversight easier without requiring deeper access, because exceptions surface visually rather than hiding in idiosyncratic formats.

Automating Consistent Advice Records

Automated meeting notes and report generation reduce variability between advisers, which reduces the need for supervisors to dig into individual files. At Brooks Macdonald, Evie cut meeting write-up time from 2.5 hours to a 30-minute review, freeing substantial time in the annual review workflow. When the draft is generated from the meeting itself, the adviser shifts from author to editor, and the supervisor reviews a consistent record rather than a blank-page gamble.

Tracking Firm-Wide Advice Data

Atlas lets supervisors query firm-wide data in plain English. Ask "which clients are due a review this quarter" and Atlas returns results with citations to source, scoped to what the supervisor is authorised to see. Adaptive Thinking, released in May 2026, makes the reasoning behind each answer visible and persistent, so a supervisor can expand the thinking block and verify how Atlas reached a given answer when reviewing a file for defensibility.

Protecting Adviser Data Permissions

Firm-wide tracking does not mean adviser data is exposed. Atlas answers from the firm's real data but is designed to scope results to the user's permission level within the platform's role-based access controls.

Configuring Firm-Wide Permissions for AdvisoryAI

We complete template configuration through a dedicated team, within two weeks, so permission structures map onto your existing document workflows rather than forcing new ones. We offer a 14-day free trial that requires no credit card, a monthly rolling agreement, a 30-day money-back guarantee, and annual plans at a 10% discount. Contact our team for current pricing on Evie, Emma, and Colin.

Managing Permission Hierarchies at Scale

Permission hierarchies are designed to work across a multi-adviser firm in layers, with firm-wide supervisors able to oversee more than practice group leads, who in turn have broader access than individual advisers and paraplanners. The hierarchy is designed so edit rights over another adviser's files are not granted by default.

Configuring Manager Access Levels

A practice group lead can oversee their group's activity and compliance results. A firm-wide supervisor can oversee the entire firm. This distinction lets you delegate oversight to group leads without creating a single compliance bottleneck at the top of the firm.

Configuring Granular Adviser Access

Paraplanner and Paraplanner Plus licences give cross-adviser access by default. The firm narrows that access by configuring Team Management, which scopes visibility to a defined group. Without that configuration in place, paraplanner access is unscoped across the firm. This reflects the operational reality of advice firms far better than static, all-or-nothing access, supporting cover arrangements and handovers through role configuration rather than shared logins.

Defining Role Based Permissions for Advice Teams

When evaluating firm-wide permissions in advice software, start with the roles, map the data each role needs, then configure the software to match. Use this checklist when scoring any platform, ours included:

Requirement

What to look for

AdvisoryAI status

Granular access

Cross-adviser access automatic for Paraplanner/Paraplanner Plus, restriction requires Team Management configuration

Opt-in scoping via Team Management

Audit trails

Document version history (who changed what and when), platform does not log who viewed a file

Yes, via document version history

Role-based visibility

See vs edit separated per role

Yes

Cross-firm scoping

Per practice group, not all-or-nothing

Yes

Back office integration

Permissions propagate to existing systems

Intelliflo, Plannr, Curo, Xplan

Managing Single-Office Firm Permissions

Single-office firms run simpler structures, but the same principles apply: advisers see their own book, supervisors see the firm, paraplanners see what they need to process. Our workflow efficiency guide shows how firms of this size put the model into practice.

Setting Access Levels by Practice Group

Each practice group carries its own adviser, paraplanner, and supervisor roles, with cross-group visibility only where configured. This is the consolidator use case, and it is why the majority of the UK consolidation market works with AdvisoryAI: oversight centralises while books stay local.

Restricting Paraplanner File Visibility

Paraplanner and Paraplanner Plus licences include cross-adviser meeting access automatically, with no setup required. Without Team Management configured, a paraplanner can access any adviser's meetings across the firm. Restriction is opt-in: firms that want to scope paraplanner visibility to specific advisers or groups do so by configuring Team Management, which limits access to the assigned scope. This protects client privacy and keeps paraplanner workload focused. The throughput impact is material: TFP Financial Planning Ltd scaled suitability report output from one to six per day with a 10% editing rate, shifting paraplanners from author to editor.

Monitoring Advice Files Across the Firm

Supervisors monitor advice files through Colin's compliance check results: colour-coded pass/fail verdicts per category, a percentage score (95.24% compliant means 40 of 42 checks passed), and specific remediation guidance such as "Add AML check documentation." Because Colin is system-agnostic, it checks any suitability report regardless of which tool produced it, giving supervisors one consistent compliance net across all advisers.

Colin catches gaps at the point of authorship, before documents leave the adviser's desk, so inconsistencies surface during drafting rather than at audit.

Ensuring Compliance While Protecting Adviser Autonomy

Compliance and adviser autonomy are not in conflict when permissions are configured correctly. This conversation on AI's role in advice explores how oversight tools can support rather than replace professional judgment. Advisers keep control of their client relationships. Supervisors get the oversight they need for Consumer Duty defensibility. The permission model is what makes both true at once.

Reducing Documentation Load for Advisers

When advisers trust that their data is private, they adopt automated documentation tools willingly, and adoption is where the time savings actually materialise. Across our customer base, suitability reports drop from 4-6 hours to under 1 hour with Emma, and research cited in our whitepaper shows annual review time down 59.8% and suitability letter time down 65.48% with automation. We back this with a 50% time-saving guarantee, with money back if it is not achieved.

Meeting Consumer Duty Requirements

The permission model supports Consumer Duty in three concrete ways:

  1. Colin checks documents against FCA Consumer Duty and COBS requirements before they leave the desk, as our file review guide explains.

  2. Supervisors can evidence consistent oversight across 100% of files rather than a sample.

  3. Atlas keeps its reasoning visible and persistent, so older queries stay auditable when a file is reviewed.

That combination is what regulators look for in a file review, and it directly supports the accountability and governance expectations set out under SM&CR, where senior managers must be able to evidence that oversight of advice processes is systematic and documented.

Centralising Advice Software Permissions

Centralising advice software permissions in one platform gives the firm a single source of truth for who can see what. Atlas enforces the model across meeting notes, reports, and compliance checks, connecting directly with Intelliflo, Plannr, and Curo through our direct Intelliflo integration so permission changes propagate into the back office systems your firm already runs. Evie extends that reach further, pushing structured meeting outputs including fact-find data covering personal information, investment details, and employment details directly into Intelliflo, Plannr, Curo, and Xplan without manual re-entry. Our back office connectivity covers the four major UK adviser platforms, like Xplan. AdvisoryAI was ranked the number one AI system among UK advisers in the AI-only category for H1 2025 by AdviserSoftware, as featured in FT Adviser, reflecting adoption by practitioners evaluating tools against real workflows.

See how our permission model works with your team structure and back office. Request a demo to view the supervisor oversight dashboard and Colin's remediation feed in your workflow.

FAQs

Can Supervisors See All Client Meetings Across the Firm?

Yes, supervisors can query firm-wide meeting data within their permission level, but they cannot edit adviser files or read private client notes outside a review context.

How Do Permissions Work for Paraplanners?

Paraplanner and Paraplanner Plus licences include cross-adviser meeting access automatically. Without Team Management configured, a paraplanner can access any adviser's meetings across the firm. Firms that want to restrict that access configure Team Management, which scopes visibility to the assigned group.

Can We Restrict Supervisor Access to Specific Advisers?

Yes, supervisor access is configurable per practice group. A supervisor can be scoped to oversee one group without visibility into others.

What Happens When an Adviser Leaves the Firm?

You deactivate the adviser's licence and reassign their book through your firm's normal handover process, so client records stay with the firm rather than the individual.

How Do Permissions Integrate With Our Back Office?

AdvisoryAI connects directly with Intelliflo, Plannr, Curo, and Iress Xplan, so permission changes propagate into the systems your firm already runs.

Key Terms Glossary

Adviser-Level Permissions: Access rights that let an adviser see and edit their own book of business, meeting recordings, and draft reports, without visibility into other advisers' client files.

Supervisor Oversight: Firm-wide visibility into documentation quality, compliance check results, and workflow status, without the ability to edit adviser files.

Firm-Wide Visibility: The ability for supervisors to see aggregated advice data across the whole firm, scoped by permission level rather than unrestricted file access.

Book of Business: The set of clients an individual adviser is responsible for, which defines the scope of their adviser-level permissions.

Serve twice the clients. Give each better advice.

Serve twice the clients. Give each better advice.

✔ Reports from your templates

✔ Reports from your templates

✔ 14-day free trial

✔ No credit card

✔ Reports from your templates

✔ 14-day free trial

✔ No credit card

>