Skip to content

Personas and jobs

Permissions combine tenant role, entity scope, business unit, case assignment, data sensitivity and action context. A role name alone cannot authorise bulk export, legal-hold release or incident closure.

PersonaPrimary jobCan approveCannot do alone
tenant ownerestablish tenant/governanceadmins, deployment settingsmass export, evidence purge
privacy adminoperate register/notices/casesroutine configuration if delegatedlegal grounds/refusals
DPO/privacy leadoversee rights/grievance/SDFresponse and escalationalter source evidence
legal reviewerdecide applicability/ground/exceptionslegal configurationoperate source connector
CISO/incident commanderrun security and breach caseincident facts/remediationfinal legal notice alone
data ownerjustify purpose/data usepurpose business factslegal ground alone
system ownerfulfil system taskstask evidenceclose parent case
processor managermanage vendors/instructionsrisk/contract workflowsign contract unless authorised
auditorinspect control/evidencefindingsmutate operational record
support agentassisted intake/messagesidentity route within policyview unrelated sensitive cases
developermanage API clients/connectorsnon-production credentialsproduction secrets/export
executive read-onlymonitor risk and decisionsnonepersonal case detail by default

Sensitive actions use maker-checker: production credential issuance, break glass, mass import/export, purpose activation, refusal, incident notification/closure, hold release, certificate signing and tenant deletion.

Customer compliance lead sees only its instruction/evidence room. Provider operations can manage a task without seeing customer content unless a time-limited support grant exists. Subprocessor owners update services/locations but cannot approve their own risk exception.

Jobs:

  • understand why specific data is requested;
  • give or deny consent without coercion;
  • withdraw as easily as grant;
  • see current preferences;
  • make and track a rights/grievance request;
  • respond to clarification securely;
  • nominate a person and revoke/update that choice;
  • receive a comprehensible breach notice and support.

The Principal never needs to know which internal team or connector is failing. The portal shows an honest status and next action without exposing security internals.

A branch/call-centre agent can create an intake reference, record the Principal’s chosen communication channel, read approved copy and upload redacted evidence to a restricted queue. The agent cannot grant consent on the Principal’s behalf without a recorded, policy-approved assisted proof.

Maintainers curate source metadata, controls, schemas, docs and releases. Legal researchers propose status changes; reviewers approve. Release managers sign configuration bundles. No maintainer can change a customer’s active legal configuration without the customer’s activation process.

  • When law changes, show affected controls/customers and obtain reviewed activation.
  • When a purpose launches, prove entity, data, route, notice, recipients, retention and owner.
  • When a Principal withdraws, stop relevant use across systems and explain lawful retention.
  • When an incident starts, preserve awareness and run every applicable clock.
  • When evidence is requested, export a scoped, signed, reproducible pack.
  • When a customer exits, return/export, revoke and delete with honest exceptions.

Every API action evaluates:

subject role + tenant + entity scope + resource assignment
+ sensitivity + purpose + action risk + maker-checker state
+ support grant + break-glass state

Denials use a stable code and correlation ID without revealing whether another tenant’s resource exists.