Team and permissions
Give people the access they need, and make sensitive actions deliberate.
- For
- Company admins
- Owner
- Identity and access
- Outcome
- Give each user the smallest role that supports their work.
- Last verified
- 2026-08-30
- Next review
- 2026-11-28
- Status
- supported
Permissions are part of the operating model. Set them around the work a person owns, then use approvals and audit-friendly workflows for actions that affect customers or the whole organization.
Start with roles
Roles define the broad set of capabilities. Teams and organization hierarchy add the context needed for ownership and visibility. Keep the number of custom combinations small enough to explain.
A good access review
- List the job each role must perform.
- Grant the smallest set of capabilities that completes that job.
- Test the role on both an allowed and a denied action.
- Review owner, team, and organization boundaries together.
- Revisit access after a person changes responsibilities.
Approvals are a safety boundary
Use approvals when the action needs a second pair of eyes. The approval record should tell the next operator what was requested, by whom, and what decision was made.