Account Team Role-Based Access & Permission Framework
under review
R
Rob Schenk
Title: Account Team Permissions and Role-Based Access Control (RBAC)
Business Problem
Today, applications inherit broad access permissions, making them available to all users with platform access. As we expand internal applications and client-facing workflows, there is a need to restrict access based on account ownership, team membership, and job function. Managing permissions separately in every application creates operational overhead, inconsistent security controls, and increases the risk of unauthorized data access.
Requested Enhancement
Create a centralized Account Team Role and Permission framework that can be used across all applications and workflows.
Requirements
- Account Team-Based Security Groups
Associate users with specific client account teams.
Support assignment by:
CAM
vCIO
Service Manager
Project Manager
Executive Sponsor
Technical Resources
Custom roles
- Role-Based Access Control
Allow administrators to define roles and permission sets centrally.
Roles should be reusable across applications.
Permissions should determine:
View access
Edit access
Administrative access
Reporting access
Workflow approval rights
- Client Data Segmentation
Users should only see data, reports, notes, action items, dashboards, and workflows for accounts they are assigned to.
Support exceptions for executives, management, and delegated access.
- Application Integration
Applications should inherit permissions from the centralized RBAC engine.
Developers should not need to build custom permission systems within each application.
New applications should be able to consume the framework as a shared service/module.
- Active Directory / Entra Integration
Integrate with existing user and group management.
Allow permissions to be assigned to:
Individuals
Security groups
Department teams
Account teams
- Audit & Governance
Track:
Who has access to each client account
Permission changes
Role assignments
Delegated access activities
Business Value
Prevents unauthorized access to client information.
Enables secure scaling of internal AI and operational applications.
Reduces development effort by providing a shared permissions framework.
Improves governance, compliance, and auditability.
Creates a consistent user experience across all applications.
Requested Outcome
A centralized Account Team and Role-Based Access Control service that can ensure permissions are managed once and consistently enforced everywhere.
J
Julia Carroll
updated the status to
under review