Skip to Content

Role model and access

A job position is a set of roles. Rights are granted by role, not on request.

For organizations where access has piled up over the years and no one remembers who granted it or why.

Where it hurts today

  • A person has moved through three job positions and keeps the access from all three.
  • Who granted an access right, and on what grounds, cannot be reconstructed.
  • Vacation cover is handled by passing along a password.
  • Incompatible duties held by one person surface during an audit.

Functional building blocks

The role as the unit

A role is bound to an object and a period, grants rights, and opens training; a job position is assembled from roles. Removes: granting rights case by case.

Assignment lifecycle

Granting, requesting, delegation, periodic access review, revocation. Removes: access that no one ever takes back.

Control and validation

Integrity checks on assignments and on the model, reports and export. Removes: surprises during an audit.

Ready-made role sets

Sets by area — sales, finance, HR, manufacturing, procurement, logistics, IT, R&D, occupational safety, compliance, clubs. Removes: designing roles from scratch.

Automation and integration

Automatic assignment, user provisioning, and programmatic access. Removes: setting up rights by hand on hiring and transfer.

End-to-end scenario

A job position is described by a set of roles → role assignment with a period → rights and assigned training → delegation during an absence → access review and revocation → an entry in the registry.

What implementation gives you

  • Access matches the current job position. Not the history of transfers.
  • Cover is recorded as a delegation. Not as a handover of an account.
  • The system checks the model. A validator and periodic access review instead of an auditor's eye.
  • A new job position is set up by assembly. From existing roles, without designing rights again.

Where to start

  1. Describe 5–10 key job positions as sets of roles.
  2. Move one entire department to the model.
  3. Turn access review and revocation into a regular procedure.

Training for this solution

Every solution comes with academy courses: the team learns the process, not the buttons. Courses run in Russian; some open only after sign-in.

Система ролей: введение и универсальные роли

For process owners and IT: how the role model works. Requires sign-in.

Управление и проекты: HR, PPM, Corporate, Compliance

For the management layer: how people, projects and rules connect. Requires sign-in.

Пользовательский курс по системе холдинга

For every user: interface and basic operations. Requires sign-in.

All academy courses

The section is assembled from platform modules already installed on this instance.

it_roles
it_roles_assignment_validator
it_roles_periodic_review
it_roles_request
it_roles_auto
it_roles_api
it_roles_dashboard
it_roles_export
it_roles_report
it_roles_validator
it_roles_club
it_roles_hrm
it_roles_crm
it_roles_finance
it_roles_hse
it_roles_it
it_roles_purchase
it_roles_logistics
it_roles_compliance