Work through the decision
A person may hold different roles in different organisations or client workspaces. Identify current membership, responsible owner and explicit records/actions granted. Distinguish designer, approver, provider, custodian, finance and external reviewer purposes. Support access needs a recorded limited scope; common operator ownership or brand context cannot bypass tenant boundaries.
A fictional worked example
A fictional agency designer works with two clients. The learner keeps each client’s artwork and budgets in separate granted workspaces. Being a designer in one project does not reveal another client’s private quote.
Evidence and authority limit
Browser-local role notes are a planning aid; actual server membership and grants must enforce permissions.
Put it into practice
Map three roles to permitted tasks and denied fields across two fictional client workspaces.
Keep this record: A current membership and explicit-grant matrix with ownership and expiry.
- Authority is organisation- and record-scoped.
- Sensitive fields have appropriate grants.
- Brand switching does not broaden access.