Support/Trust & Security/DataRoles: data and action permissions

Trust & Security

DataRoles: data and action permissions

DataRoles define what tenant data a person can see, add to, change, delete, export, or use through approved AI paths.

Controls
Data and action permissions
Per person
One or multiple DataRoles
Combination
Active grants accumulate

A DataRole is the data-permission part of tenant security. It defines what a person may see and what they may add to or change. A person can hold one DataRole or several, depending on their responsibilities.

What DataRoles can grant

GrantWhat it means
ReadView permitted records and fields.
Create / addCreate new records through an authorized module or workflow.
EditChange permitted records and fields.
DeleteUse supported deletion operations where the record and workflow allow it.
ExportExport permitted records when export is enabled.
AI readAllow eligible permitted records into secured AI retrieval; secure and AI-excluded fields remain excluded.
Named permission keysPerform specific operations such as an approval or specialized module action.

Multiple DataRoles combine

Active role grants are cumulative in the current permission envelope. If one assigned role grants record reading and another grants editing, the user can receive both grants, still subject to every other check. Adding a role can therefore widen access; removing one can narrow it.

DataRoles do not erase Location scope. A user with edit permission for work orders and access only to the Las Vegas office may edit authorized Las Vegas work orders, not Reno work orders. Field security, record state, ownership, workflow locks, and action-specific rules may narrow an apparently broad role further.

DataRole is not User Type

A User Type can show the Support menu while DataRoles decide whether that person is a read-only support observer, a case editor, or an approver. Two people can share the same User Type and see the same navigation while having different data access.

Least-privilege examples

  • Cases Reader: read permitted cases without create, edit, delete, or export.
  • Case Agent: read, create, and edit permitted cases, but not approve refunds.
  • Billing Approver: receive only the explicit billing/approval capabilities required by that job.
  • AI-enabled Analyst: read permitted records and use AI retrieval, without gaining edit or export access.
Note

AI remains inside DataRole permissions. CanAiReadRecords can only enable AI use of records the person is otherwise permitted to read, and secure or AI-excluded fields stay out of model context.

Reviewing a DataRole change

  1. List the exact reads, additions, changes, exports, approvals, and AI operations the job requires.
  2. Check every other role already assigned to the person because grants combine.
  3. Confirm the intended Location memberships.
  4. Test allowed and denied records, fields, searches, downloads, AI results, and mutations.