THE STARTING POINT
Translate user roles into understandable permission decisions and review scenarios.
Describe the work behind each role.
List the actions each role needs to perform, such as viewing a record, changing a value or approving a request. Separate business responsibility from job title. Two people with similar titles may need different access, and a broad administrator role should not become the default answer to every requirement.
Check exceptional situations.
Discuss temporary cover, role changes and tasks requiring approval from another person. Include how access is requested and removed. Test whether sensitive actions remain restricted when a user follows an unusual route through the interface, rather than checking only the visible navigation options.
Keep permission changes traceable.
Agree who owns the role definitions and how future changes are reviewed. Describe the information administrators need to investigate an unexpected access result. Revisit the design when workflows change so that permissions continue to match the responsibilities they were intended to support.
TAKE THE NEXT STEP
Your discovery checklist
- List permitted actions for each business role.
- Check temporary cover, role changes and approval routes.
- Assign an owner for reviewing permission changes.
