Glossary term

Role-based access control

Role-based access control is a method of assigning system permissions according to defined job or process roles rather than granting each user an unrelated set of rights. In procurement, roles can govern who views, creates, evaluates, approves, changes, or exports records. Good governance includes least privilege, role ownership, testing, periodic review, and removal when responsibilities change.

Role-based access control is a method of assigning system permissions according to defined job or process roles rather than granting each user an unrelated set of rights. In procurement, roles can govern who views, creates, evaluates, approves, changes, or exports records. Good governance includes least privilege, role ownership, testing, periodic review, and removal when responsibilities change.

In plain English

It gives people system access based on the responsibilities they are authorized to perform.

Illustrative example

At Northstar Industrial Systems, supplier evaluators can score assigned criteria, while only designated approvers can authorize the final award state.

Related terms
Access control; Segregation of duties; Approval workflow; Single sign-on
Lifecycle stages
All stages
Stakeholders
IT and Security; Procurement; Audit; Approver

Continue your evaluation

Turn useful reading into the next procurement decision.

Continue with a guide, walkthrough, calculator, or a focused workflow conversation.

Explore the Resource CenterBring a priority workflow