The first time a brokerage opens a second office, someone has to decide whether the two can see each other’s pipelines. It gets treated as a systems question. It is not.
What a branch should see
Its own leads, its own listings, its own numbers. That much is uncontroversial. The argument is always about the listings: a Business Bay client who wants a Marina apartment should reach the Marina stock without the Marina agent losing the listing or the Business Bay agent losing the client.
That is a permission model, not a policy document. Shared listing visibility, separate lead ownership, and an explicit referral path.
Teams inside branches
Off plan, secondary and leasing run different pipelines with different stages and different SLAs. If they share one pipeline because the system only has one, your reporting will average three unrelated businesses together and tell you nothing.
Roles are about damage, not seniority
A listing administrator who can approve and publish is a different risk from an agent who can create a draft. A marketing user who needs media access does not need the finance module. Role design is a question of what each person could break, not of what their title is.
Enforce it in the API
A permission that only hides a menu item is a suggestion. The check has to happen where the data is, on every request, or you have not actually restricted anything.
