Feature deep-dive

Roles, Permissions & White-Label Branding: Software That Bends to the Firm

Who sees the money, whose logo is on the invoice, which modules even exist — the control layer is where IP software either fits your practice or fights it. A screenshot tour of how IPBases handles it.

Published August 2026 · 8 min read

Software you configure, not software you adapt to

Every IP practice runs differently: different fee structures, different confidentiality rules, different people allowed to see the money. Off-the-shelf tools force the firm to bend; IPBases takes the opposite stance — the system bends to the firm. This post walks through the control layer: roles and granular permissions, permission groups, branding, and module toggles, with real screenshots from the admin side.

Five built-in roles — and “Login as” for support

IPBases users and permissions screen with built-in roles Owner, Administrator, Manager, Staff and Read-only, plus per-user Permissions, Activity and Login-as buttons
Users & Permissions — five built-in roles from Owner to Read-only, with per-user Permissions, an Activity log, and a Login-as button for troubleshooting exactly what a user sees.

Out of the box: Owner (unrestricted), Administrator, Manager (day-to-day operations, no system admin), Staff (create/edit, no delete), and Read-only for receptionists, interns or accountants who need reference access. Users can be assigned to offices, every user has an activity trail, and admins can log in as any user — the fastest way to answer “why can’t I see X?” ever invented.

Granular permissions with hard denies

IPBases granular permissions editor showing permission groups Finance Access and No Financials, and per-action Inherit, Allow and Never toggles with a result analyzer badge
The permission editor — per-action Inherit / Allow / Never toggles, stackable permission groups like “No Financials”, and an analyzer badge showing the final computed result for every permission.

Underneath the roles sits a per-action matrix — clients.view, associates.delete, and so on — with three states: Inherit (the role and groups decide), Allow, and Never — a hard deny that beats everything, including user-level allows. Permission groups like “Finance Access” or “No Financials” stack on top of roles, so “paralegals never see invoices” is one group assignment, not twenty checkbox edits. The analyzer badge next to every permission shows the final computed answer and where it came from — no guessing why someone can or can’t do something.

White-label branding — down to the invoice logo

IPBases branding page with email signature editor and module toggles for Trademarks, Clients, Associates, Invoices, Payments, Offers, Litigation, Tasks, Mail Log, Reports and Client Portal
Branding & Modules — a rich email-signature editor on the left; on the right, one-click module toggles that hide entire features the firm doesn’t use.

The firm’s name and logos appear everywhere the software touches the outside world: five separate logo slots (sidebar, login page, email header, invoice PDF, favicon), default invoice subject and message templates with merge placeholders, and an email signature editor whose output lands on every outgoing message. And if the firm doesn’t use a module — say, Offers or Litigation — switch it off: it disappears from the sidebar for everyone, with the data preserved if you ever switch it back on.

Reference data: your statuses, your services, your world

IPBases admin control panel with reference data managers for trademark statuses, service types, IP types, offices, a 246-country database, currencies, industries and Nice classes
The Admin Control Panel — every dropdown in the system is editable data: TM statuses with color coding, 19 service types, offices, a 246-country database with flags, currencies, industries, and Nice classes 1–45.

Nothing in the dropdowns is hard-coded. Trademark statuses (with color coding), service types and their fees, IP types, the firm’s offices, a full 246-country database, currencies, client industries and the Nice classes are all managed data. Add a status your local office uses, retire one you don’t, and the whole system follows.

The deeper toolbox

IPBases system management cards including email templates, automation, sidebar editor, file categories, temporary access links, demo data, mail settings, Stripe payment settings, storage backend, database backup, global trademark search, and audit log
System Management — email templates, renewal automation, a sidebar editor, temporary access links, Stripe payment settings, pluggable storage (Local/S3/R2), scheduled database backups, global TM search providers, and the audit log.

The same panel goes further than most firms will ever need: a sidebar editor (rename, reorder, hide, add custom links with your own icons), field visibility and custom fields on records, file categories that drive the wizard’s Files tab, temporary access links (expiring auto-login for demos and audits), demo data seeding for training, pluggable storage backends (local, Amazon S3, Cloudflare R2), scheduled database backups with retention, global TM search provider configuration (USPTO, EUIPO), and an append-only audit log tracking every change in the system. Because IPBases is self-hosted, all of this is yours to configure — no support ticket to a vendor required.

Related reading

Configure it once, own it forever

Roles, hard-deny permissions, white-label branding and module toggles — on a self-hosted system your firm controls completely.

Book a demo → See pricing →
IPBases