Review device — not a security control. It changes what this prototype shows, never what anyone is permitted to do.
Roles and permissions
The two personas Strategic Accounts administration recognises, what each one may do, and the full action matrix behind the navigation. The matrix is computed from the shipped code, so it cannot drift from it. Changing a cell records a request; it does not change what the running application enforces.
Personas
2
Actions governed
43
Cells in the matrix
86
Overrides recorded
0
Open questions answered
0
Pending changes
0
Personas
What each persona is for, what it may and may not do, and which screens it reaches.
Administrator
Owns the configuration of this application, reaches every area and may change anything not mastered elsewhere.
Allowed
Configure reference data and dashboard links
Set widget permission defaults and per-account and per-person access grants
Set the customer exposure ceiling
Administer internal users, external access and the access policy
Change platform settings and notification templates
Not allowed
Change the account hierarchy, which is mastered in the CRM and read here
Change which widgets exist or what an account starts with, which are fixed in code
Change which widgets sit on one account's wall, which stays with the account manager in the Strategic Account Management application
Expose a widget to a customer, which is also done there within the ceiling set here
Remove the last remaining administrator
Screens
All screens
Read-only auditor
Reads configuration and change history across the whole application and changes nothing anywhere.
Allowed
Open every area of the application
Read configuration, change history and integration events
Export and cite what they see
Not allowed
Create, edit, deactivate or reassign anything
Grant or remove access
Screens
All screens
Rules that apply to everyone
Constraints that hold whichever persona is acting.
Nothing is deleted. A record is deactivated and keeps its history.
Every change that widens or narrows access is written to the audit trail with the reason given.
A change made here is a recorded request. The running application keeps behaving the way the shipped defaults describe until the change has been built.
The account hierarchy — global accounts, regional clusters and Class A accounts — is mastered in the CRM. It is read here and changed there.
Open questions
The open questions are no longer held here. They span account data, roles, portal access, retention and brand as well as permissions, so they sit in one register of their own: Open questions. 0 of 10 carry a recorded response.
Widget permission defaults
What each role level may do with each widget on a Class A account working area is a separate register: Widget permission defaults. This screen governs who administers this application; that one governs what account teams see in Strategic Account Management.
Action matrix
Every navigable area and named exception, computed from the shipped code.
Action
Administrator
Read-only auditor
Configuration
Open reference data
Change reference data
Open dashboard links
Change dashboard links
Open widget composition
Change widget composition
Access
Open account hierarchy
Change account hierarchy
Open internal users
Change internal users
Open external access
Change external access
Open widget permission defaults
Change widget permission defaults
Open access grants
Change access grants
Open customer exposure ceiling
Change customer exposure ceiling
Open customer column visibility
Change customer column visibility
Open access policy
Change access policy
Grant or remove access to this application
Deactivate an internal user and reassign their accounts
Integration
Open crm field mapping
Change crm field mapping
Open integration log
Change integration log
Platform
Open notifications
Change notifications
Open tutorials
Change tutorials
Open settings
Change settings
Open business rules
Change business rules
Open roles & permissions
Change roles & permissions
Open open questions
Change open questions
Open changelog
Change changelog
Turn a deferred capability on
None of this is enforced server-side in the prototype. Persona switching re-renders navigation and disables controls so the shape of each role can be reviewed; the Power Apps build must re-implement these rows as Dataverse security roles.