Trust & Security
DataRoles: data and action permissions
DataRoles define what tenant data a person can see, add to, change, delete, export, or use through approved AI paths.
A DataRole is the data-permission part of tenant security. It defines what a person may see and what they may add to or change. A person can hold one DataRole or several, depending on their responsibilities.
What DataRoles can grant
| Grant | What it means |
|---|---|
| Read | View permitted records and fields. |
| Create / add | Create new records through an authorized module or workflow. |
| Edit | Change permitted records and fields. |
| Delete | Use supported deletion operations where the record and workflow allow it. |
| Export | Export permitted records when export is enabled. |
| AI read | Allow eligible permitted records into secured AI retrieval; secure and AI-excluded fields remain excluded. |
| Named permission keys | Perform specific operations such as an approval or specialized module action. |
Multiple DataRoles combine
Active role grants are cumulative in the current permission envelope. If one assigned role grants record reading and another grants editing, the user can receive both grants, still subject to every other check. Adding a role can therefore widen access; removing one can narrow it.
DataRoles do not erase Location scope. A user with edit permission for work orders and access only to the Las Vegas office may edit authorized Las Vegas work orders, not Reno work orders. Field security, record state, ownership, workflow locks, and action-specific rules may narrow an apparently broad role further.
DataRole is not User Type
A User Type can show the Support menu while DataRoles decide whether that person is a read-only support observer, a case editor, or an approver. Two people can share the same User Type and see the same navigation while having different data access.
Least-privilege examples
- Cases Reader: read permitted cases without create, edit, delete, or export.
- Case Agent: read, create, and edit permitted cases, but not approve refunds.
- Billing Approver: receive only the explicit billing/approval capabilities required by that job.
- AI-enabled Analyst: read permitted records and use AI retrieval, without gaining edit or export access.
AI remains inside DataRole permissions. CanAiReadRecords can only enable AI use of records the person is otherwise permitted to read, and secure or AI-excluded fields stay out of model context.
Reviewing a DataRole change
- List the exact reads, additions, changes, exports, approvals, and AI operations the job requires.
- Check every other role already assigned to the person because grants combine.
- Confirm the intended Location memberships.
- Test allowed and denied records, fields, searches, downloads, AI results, and mutations.