Roles and permissions
Named permissions for all products, granted by role and its scope from Granted roles, with segregation of duties that delegation can’t override. N-V8-04 CORE-REQ-007 N-D2-02 N-D2-03
General roles
5.1- Account ownerHolders · Revoked only by transferring ownership CORE-CALC-003Critical
- Account owner’s delegateHolders · Inherits all of the account owner’s permissions in the organization and all shared apps, including Internal Audit, except granting this role. Only the account owner grants it, in their own right, and the last delegate’s role can’t be withdrawn
- CEOHolders · Account owner permissions except system administration, and grants in any scope except “Account owner’s delegate”
- Unit managerHolders · Assigns within their unit and the units below it, grants roles at or below their position’s level themselves, and higher roles with the chief executive’s knowledge
- SupervisorHolders · N1 · Whole organization · Views all records and pages of one app, without approving or editingView only
- HR officerHolders · N1 · Whole organization · HR in Core + Talent app
- HR officer (sub-unit)Holders · N2 · Their unit and below · HR in Core + Talent app
- Supervisor (sub-unit)Holders · N3 · Their unit and below · Views without approving or editingView only
- Product managerHolders · Products
- ApproverHolders · Within delegation limits
- ReviewerHolders · Reviews, returns or recommends approval from the task drawer in the Task center IAM-BR-001
- Member / editorHolders
- ViewerHolders
- AuditorHolders · Read-only, no edits to the original
- Integration accountHolders Not calculated · Non-human identityAutomated
- Project managerHolders · Granted at the level of a single projectProject level
- Project team memberHolders · Granted at the level of a single projectProject level
Level of each role in the structure
| Role | Level | Scope |
|---|
Custom roles
Role ← permission matrix
Machine-readable named permissions register · Scope: workspace
| Permission | Account owner | Org manager | Product manager | Approver | Reviewer | Editor | Viewer | Auditor |
|---|---|---|---|---|---|---|---|---|
| Organization | ||||||||
| Read organizational units org.unit.read | ||||||||
| Propose structure changes org.structure.propose | — | — | — | — | — | — | ||
| Approve structure changes org.structure.approve | ≠ | — | ◐ | — | — | — | ||
| Identity and access | ||||||||
| Invite users iam.user.invite | ◐ | — | — | — | — | — | ||
| Grant roles iam.role.grant | ◐ | — | — | — | — | |||
| Approve break-glass access iam.breakglass.approve | 2× | — | — | — | — | — | — | |
| Measurement and periods | ||||||||
| Define KPIs measure.indicator.define | — | — | — | ◐ | — | — | ||
| Hard close of periods period.lock.hard | — | — | — | — | — | — | ||
| Export audit log audit.log.export | ◐ | — | — | — | — | — | ||
Granted◐Conditional on the holder’s scope≠Provided the proposer isn’t also the approver2×Two-person approval—Not grantedBlocked by segregation of duties
Version 12 · Approved on September 1, 2026Active conflicts needing a decision:
Temporary delegation does not override the segregation-of-duties rule. Every exception carries an owner, a duration, and a justification. N-D2-03 Minimum SoD rules
| Rule | Permission A | Permission B | Level | Conflicts |
|---|
Active and scheduled delegations
The unified delegation engine in the Core
| Delegator ← delegate | Scope | Limit | Duration | Status |
|---|
Delegation rules
The delegate’s limit cannot exceed the delegator’s limit
No delegation that conflicts with a rule SoD
Maximum duration of 90 days with automatic expiry
Every decision is logged as “on behalf of” in the decision log
No chained delegation (the delegate cannot re-delegate)
Campaign for Q3 2026
Grants certified
Ends September 30
Suggested for revocation
Overdue reviewersNot calculated
Your team’s grants awaiting your certification
| User | Role | Scope | Last used | Recommendation | Decision |
|---|
Break-glass access request awaiting your approval
SUP-4471 · INC-2291 · 2026-09-24 09:56
- Requester
- Eng. Yazan Al-Harithi — Platform Support team
- Reason
- Migration of Q3 indicator values for the “Finance Department” unit failed, and automatic retry was not possible.
- Requested resources
measure.actual:*@OU-SS-FINevents.dlq:read- Window
- 4 hours (default maximum) · expires automatically
- Export
- Prohibited except with explicit additional approval IAM-SEC-024
The approver is notified at start and end, and every view and edit is logged in a separate audit log that can’t be erased operationally. IAM-SEC-023
Recent break-glass sessions
- INC-2244 · 2 hours 10 minutes31 August 2026 · 14 views · no exportClosed
- INC-2190 · 45 minutes2 August 2026 · 3 views · 1 editClosed
Permission catalog
| Permission | App and action | Scopes | Who holds it |
|---|
Active delegations across all apps
| App | Delegator | Delegate | Scope | Duration |
|---|