Role-Based Access
Role-based access grants actions according to a person's job and the records they are authorised to use. It should be tested with ordinary users and across company boundaries.
A worked example
A practical example to make the concept clear.
| Step | Illustrative record and result |
|---|---|
| Starting record | Example sales role: read customers and create quotations for Company A. |
| Change or calculation | Finance approves refunds; warehouse validates deliveries. A salesperson should be denied these approval actions if the agreed role excludes them. |
| Meaning and exception | Test with the ordinary sales account: allowed quotation succeeds; prohibited refund approval and Company B records are denied. A role name alone does not prove isolation. |
Why it matters
Map read, write, approve and export actions to each role. This gives people the tools they need while protecting sensitive decisions and records.
Make it practical
Can an ordinary user complete their task while being denied another company’s records? Test the answer with the exact release and application package under consideration. Explore Datrylo applications.