What Are Role-Based Permissions?

Role-based permissions are defined system actions and data-access rights assigned through a user's job role.

Role-based permissions are defined system actions and data-access rights assigned through a user's job role. They determine what people can view, create, change, approve or administer.

How do role-based permissions work?

Administrators group permissions into roles and assign users to those roles. A finance preparer may create payments while an approver can authorize but not change beneficiary data.

Which permissions should be separated?

  • User and role administration
  • Master-data maintenance
  • Transaction creation
  • Approval and release
  • Reconciliation and adjustment
  • Audit-log access

Permissions vs. roles

A permission is a specific allowed action. A role is a governed bundle of permissions associated with responsibilities. One user may hold several roles, subject to conflict rules.

What risks arise?

Broad roles, inherited access and conflicting assignments can violate least privilege. Hidden service accounts and emergency access also need review.

How should permissions be governed?

Define owners, approval, periodic review, joiner-mover-leaver controls and logs. Test whether users can combine actions that should require separate people.

Related Terms