Skip to content

Roles and permissions

The two personas Strategic Accounts administration recognises, what each one may do, and the full action matrix behind the navigation. The matrix is computed from the shipped code, so it cannot drift from it. Changing a cell records a request; it does not change what the running application enforces.

Personas
2
Actions governed
43
Cells in the matrix
86
Overrides recorded
0
Open questions answered
0
Pending changes
0

Personas

What each persona is for, what it may and may not do, and which screens it reaches.

Administrator

Owns the configuration of this application, reaches every area and may change anything not mastered elsewhere.

Allowed

  • Configure reference data and dashboard links
  • Set widget permission defaults and per-account and per-person access grants
  • Set the customer exposure ceiling
  • Administer internal users, external access and the access policy
  • Change platform settings and notification templates

Not allowed

  • Change the account hierarchy, which is mastered in the CRM and read here
  • Change which widgets exist or what an account starts with, which are fixed in code
  • Change which widgets sit on one account's wall, which stays with the account manager in the Strategic Account Management application
  • Expose a widget to a customer, which is also done there within the ceiling set here
  • Remove the last remaining administrator

Screens

All screens

Read-only auditor

Reads configuration and change history across the whole application and changes nothing anywhere.

Allowed

  • Open every area of the application
  • Read configuration, change history and integration events
  • Export and cite what they see

Not allowed

  • Create, edit, deactivate or reassign anything
  • Grant or remove access

Screens

All screens

Rules that apply to everyone

Constraints that hold whichever persona is acting.

  • Nothing is deleted. A record is deactivated and keeps its history.
  • Every change that widens or narrows access is written to the audit trail with the reason given.
  • A change made here is a recorded request. The running application keeps behaving the way the shipped defaults describe until the change has been built.
  • The account hierarchy — global accounts, regional clusters and Class A accounts — is mastered in the CRM. It is read here and changed there.

Open questions

The open questions are no longer held here. They span account data, roles, portal access, retention and brand as well as permissions, so they sit in one register of their own: Open questions. 0 of 10 carry a recorded response.

Widget permission defaults

What each role level may do with each widget on a Class A account working area is a separate register: Widget permission defaults. This screen governs who administers this application; that one governs what account teams see in Strategic Account Management.

Action matrix

Every navigable area and named exception, computed from the shipped code.

ActionAdministratorRead-only auditor
Configuration
Open reference data
Change reference data
Open dashboard links
Change dashboard links
Open widget composition
Change widget composition
Access
Open account hierarchy
Change account hierarchy
Open internal users
Change internal users
Open external access
Change external access
Open widget permission defaults
Change widget permission defaults
Open access grants
Change access grants
Open customer exposure ceiling
Change customer exposure ceiling
Open customer column visibility
Change customer column visibility
Open access policy
Change access policy
Grant or remove access to this application
Deactivate an internal user and reassign their accounts
Integration
Open crm field mapping
Change crm field mapping
Open integration log
Change integration log
Platform
Open notifications
Change notifications
Open tutorials
Change tutorials
Open settings
Change settings
Open business rules
Change business rules
Open roles & permissions
Change roles & permissions
Open open questions
Change open questions
Open changelog
Change changelog
Turn a deferred capability on

None of this is enforced server-side in the prototype. Persona switching re-renders navigation and disables controls so the shape of each role can be reviewed; the Power Apps build must re-implement these rows as Dataverse security roles.