Access and roles
Grant access from an approved request that identifies the person's job function, business areas, edit needs, and any separately approved sensitive-data access.
- Confirm the requestor, approver, user identity, and environment.
- Select the narrowest standard role or module permissions that meet the need.
- Treat sensitive-data access as a separate decision.
- Save the assignment and have the user test an expected allowed action.
- Verify a representative action outside the role remains unavailable.
- Record the approval and review or expiration date.
Remove or adjust access promptly when duties change. Periodically review inactive accounts, privileged roles, sensitive-data readers, and exceptional assignments. Do not create a broad role to resolve one unexplained screen error.