The first time a practice adds a second adviser, a quiet question appears: who should be able to see what?
It is easy to postpone. It is much harder to unwind later, once everyone has seen everything.
Roles are a growth decision, not just a security one
Access rules are usually framed as protection. In a growing practice they are really about focus: a consultant working their own clients does not need the whole book in front of them, and the whole book in front of them is mostly noise.
Revenue should be something you grant, not something everyone inherits by default.
A structure that scales
- Principal — the entire book, including recurring premium and commission.
- Consultant — their own employer clients, without the revenue view.
- Support — the administrative record without the commercial layer.
POPIA sits underneath all of it
Scoping personal information to the people who genuinely need it is not only good practice — it is the shape South African data rules expect. Getting roles right is most of the work of being POPIA-aware.
Set it before you need it
The right time to define roles is when the team is small enough that the conversation is easy. Doing it early means the structure is simply how the practice works, rather than a change imposed on people later.