Set responsibilities and permissions
Match access and decision authority to the work a person or integration performs.
Begin with responsibilities
Define who performs the work, who reviews it, who administers the workspace, and who can approve changes. Scope access to the relevant organization, site, records, and actions. Read access and approval authority answer different questions.
Separate responsibilities where needed
| Responsibility | Typical access to evaluate |
|---|---|
| Operator | View instructions, record observations, and complete permitted steps. |
| Reviewer | Inspect evidence and make assigned decisions. |
| Administrator | Manage configuration and access under change controls. |
| Integration identity | Read or act within a specific automated workflow. |
| AI agent | Retrieve or propose within assigned scope; use explicit approval gates. |
Test the boundaries
- Verify both allowed and denied actions with representative roles.
- Confirm restrictions on sensitive records and cross-site access.
- Avoid sharing personal credentials with integrations.
- Revoke access when responsibilities end, and review permissions periodically.