Skip to main content

Access and roles

Grant access from an approved request that identifies the person's job function, business areas, edit needs, and any separately approved sensitive-data access.

  1. Confirm the requestor, approver, user identity, and environment.
  2. Select the narrowest standard role or module permissions that meet the need.
  3. Treat sensitive-data access as a separate decision.
  4. Save the assignment and have the user test an expected allowed action.
  5. Verify a representative action outside the role remains unavailable.
  6. Record the approval and review or expiration date.

Remove or adjust access promptly when duties change. Periodically review inactive accounts, privileged roles, sensitive-data readers, and exceptional assignments. Do not create a broad role to resolve one unexplained screen error.