Access in Carerealm is per-area. A user added to one area only sees that area. Three modes determine who's on the access list.
1. Named users (default)
The Permissions section of Area settings has a General Access (non-admin) multi-select. Pick the users who should have access; everyone else is locked out.
2. Global access
Flip the Global Access (everyone in your organisation can access) switch and every signed-in user in your realm sees this area. Carerealm asks for confirmation — it's a big change.
Heads up — Use global access carefully. For sensitive areas (e.g. someone with safeguarding restrictions) keep it on the named list and grant access deliberately.
3. Inherited from parent group
When you assign an area to a parent group (see Parent groups), it picks up the group's access list automatically. Anyone added to the group inherits access to every area under it.
Moderators
A Moderator is a user from the access list who can also edit settings, About, and the area's structure. The Moderators (subset of above) multi-select in Permissions lets you pick them — only people already in General Access are eligible. See Roles and moderators.
Realm admins
Realm admins automatically have access to every area for audit / break-glass purposes. They don't appear on the access list; their permission is implicit.