Personas and jobs
Permissions combine tenant role, entity scope, business unit, case assignment, data sensitivity and action context. A role name alone cannot authorise bulk export, legal-hold release or incident closure.
Enterprise roles
Section titled “Enterprise roles”| Persona | Primary job | Can approve | Cannot do alone |
|---|---|---|---|
| tenant owner | establish tenant/governance | admins, deployment settings | mass export, evidence purge |
| privacy admin | operate register/notices/cases | routine configuration if delegated | legal grounds/refusals |
| DPO/privacy lead | oversee rights/grievance/SDF | response and escalation | alter source evidence |
| legal reviewer | decide applicability/ground/exceptions | legal configuration | operate source connector |
| CISO/incident commander | run security and breach case | incident facts/remediation | final legal notice alone |
| data owner | justify purpose/data use | purpose business facts | legal ground alone |
| system owner | fulfil system tasks | task evidence | close parent case |
| processor manager | manage vendors/instructions | risk/contract workflow | sign contract unless authorised |
| auditor | inspect control/evidence | findings | mutate operational record |
| support agent | assisted intake/messages | identity route within policy | view unrelated sensitive cases |
| developer | manage API clients/connectors | non-production credentials | production secrets/export |
| executive read-only | monitor risk and decisions | none | personal case detail by default |
Sensitive actions use maker-checker: production credential issuance, break glass, mass import/export, purpose activation, refusal, incident notification/closure, hold release, certificate signing and tenant deletion.
Processor profile
Section titled “Processor profile”Customer compliance lead sees only its instruction/evidence room. Provider operations can manage a task without seeing customer content unless a time-limited support grant exists. Subprocessor owners update services/locations but cannot approve their own risk exception.
Data Principal
Section titled “Data Principal”Jobs:
- understand why specific data is requested;
- give or deny consent without coercion;
- withdraw as easily as grant;
- see current preferences;
- make and track a rights/grievance request;
- respond to clarification securely;
- nominate a person and revoke/update that choice;
- receive a comprehensible breach notice and support.
The Principal never needs to know which internal team or connector is failing. The portal shows an honest status and next action without exposing security internals.
Assisted user
Section titled “Assisted user”A branch/call-centre agent can create an intake reference, record the Principal’s chosen communication channel, read approved copy and upload redacted evidence to a restricted queue. The agent cannot grant consent on the Principal’s behalf without a recorded, policy-approved assisted proof.
Maintainer and legal researcher
Section titled “Maintainer and legal researcher”Maintainers curate source metadata, controls, schemas, docs and releases. Legal researchers propose status changes; reviewers approve. Release managers sign configuration bundles. No maintainer can change a customer’s active legal configuration without the customer’s activation process.
Core jobs-to-be-done
Section titled “Core jobs-to-be-done”- When law changes, show affected controls/customers and obtain reviewed activation.
- When a purpose launches, prove entity, data, route, notice, recipients, retention and owner.
- When a Principal withdraws, stop relevant use across systems and explain lawful retention.
- When an incident starts, preserve awareness and run every applicable clock.
- When evidence is requested, export a scoped, signed, reproducible pack.
- When a customer exits, return/export, revoke and delete with honest exceptions.
Permission test
Section titled “Permission test”Every API action evaluates:
subject role + tenant + entity scope + resource assignment+ sensitivity + purpose + action risk + maker-checker state+ support grant + break-glass stateDenials use a stable code and correlation ID without revealing whether another tenant’s resource exists.