Skip to main content

Roles & Permissions

Purpose: Define who can do what - the RBAC model focused on roles composed of permissions and applied to users/groups/nodes.

Design & Governance​

  • Principle of least privilege: create narrow roles for specific tasks (e.g., “Support: Reset MFA”).
  • Role naming: include scope and purpose in name (e.g., “Billing:InvoiceManager”, “Security:ReadAudit”).

Create a Role​

  • Step 1: New role → choose a clear name and description.

  • Step 2: Select permissions needed for the role; prefer least privilege.

  • Step 3: Assign to a user (see Users) or group (see Groups), or attach to a node (Hierarchy) for scoped application.

Role Assignment Lifecycle​

  • Step 1: Request and approval flows to grant elevated roles temporarily.
  • Step 2: Use time-bound role assignments for temporary work (e.g., contractor access).

Access Reviews & Audits​

  • Schedule periodic access reviews for critical roles.
  • Keep evidence of review and remediations in the Audit Log.


Troubleshooting​

  • Role not granting expected access:
    • Verify that permissions included actually match the operation and that no deny policy overrides them.

Best Practices​

  • Use role templates and document their use-cases.
  • Avoid role sprawl - retire unused roles.