Role-based access control is a method of assigning system permissions according to defined job or process roles rather than granting each user an unrelated set of rights. In procurement, roles can govern who views, creates, evaluates, approves, changes, or exports records. Good governance includes least privilege, role ownership, testing, periodic review, and removal when responsibilities change.
In plain English
It gives people system access based on the responsibilities they are authorized to perform.
Illustrative example
At Northstar Industrial Systems, supplier evaluators can score assigned criteria, while only designated approvers can authorize the final award state.
- Related terms
- Access control; Segregation of duties; Approval workflow; Single sign-on
- Lifecycle stages
- All stages
- Stakeholders
- IT and Security; Procurement; Audit; Approver