The eleven shipped roles cover the common cases. For the rest you create your own — and Illizeo lets you measure its effect before assigning it to anyone.
Step-by-step #
-
Create the role and name it in both languages #
A badly named role ends up being stacked “just in case”. Write what it allows, not the department that holds it.
-
Set the scope before the rights #
That is the setting that determines real exposure. A high tier over a narrow population is safer than a low tier over everyone.
-
Tick the rights in the matrix #
The matrix is organised by menu. Each box sets a code at a tier: Access, Execute or Admin for a feature; View, Edit, Insert, Delete or History for a field. There are no generic “Export” or “Approve” verbs: approving, for instance, is one named code among others.
-
Measure the impact before assigning #
Two tools for that: the role’s impact preview, and the preview against a specific employee, which shows what this role would grant over that person. More reliable than signing in as them.
-
Add the members #
Manually, or by computed membership if you want the role to follow the organisation rather than a list you have to maintain.
-
Review the role’s history #
Every role keeps a trace of its changes. That is where you find the widened right nobody can explain any more.
Common use cases #
| What to set | Where | Note |
|---|---|---|
| Role name | Role record | Translatable: a role carries its label in each of the workspace’s languages |
| Scope | Role record | Who the role acts on: self, their team, everyone, or a custom population |
| Rights | Permission matrix | One code and its tier at a time |
| Members | Members tab | Added manually, or computed membership |
| Two-factor | Role security tab | If your plan includes it |
| Duration | Role record | A temporary role carries a start date and an end date |
FAQ #
How many roles can we create?
There is no technical limit. The limit is human: past fifteen or so, nobody knows who holds what.
Can a role be duplicated?
No, there is no duplicate button. A new role starts from a blank matrix.
Can we sign in as a user to check?
That is not the intended tool. Previewing against a target employee answers the same question without borrowing their identity — and without leaving their trace in the logs.
RBAC or ABAC?
Both. The role carries the capabilities, and attribute filters narrow the population it acts on.
Does a ticked right always take effect?
If a box has no visible effect, report it rather than working around it: that is a defect to fix, not a subtlety of configuration.
What does not exist #
No role duplication. No “simulate as” mode. No “role audit” report listing each role’s last use. No inheritance between roles: a custom role does not derive from a shipped one.
