Skip to content
Seco

Governance

Roles & permissions

The web roles, the scope each one carries, and the capability matrix defaulted from the permissions the portal actually enforces. Retune anything and it becomes a change request until the guard is built in code.

Personas

Anonymous

The public. Sees the sign-in placeholder and nothing else.

Allowed
  • Reach the sign-in placeholder
Not allowed
  • Read any account, question or rule in this prototype
Screens
Sign-in

Authenticated

Baseline for every signed-in contact. Placeholder — no data by itself.

Allowed
  • Open the three surfaces this prototype ships: overview, open questions, business rules
Not allowed
  • Pending confirmation (P8-Q4) — how a customer user signs in is not settled
Screens
OverviewOpen questionsBusiness rules

Customer contact (to confirm)

Placeholder for the customer user. Who this is — procurement, engineering, per-site or global — is P8-Q1. Pending confirmation.

Allowed
  • Open the three surfaces this prototype ships: overview, open questions, business rules
Not allowed
  • See any other account's data — Pending confirmation (P8-Q3) on how isolation is enforced
  • Pending confirmation (P8-Q10) — whether this persona may change portal exposure at all
Screens
OverviewOpen questionsBusiness rules

Scope matrix

What each persona reads, edits and approves, and at which level. A cell changed from the built-in decision is outlined and listed above as a change request.

PersonaReadEditApproveLevelReporting
AnonymousPending confirmationPending confirmation
AuthenticatedPending confirmationPending confirmation
Customer contact (to confirm)Pending confirmationPending confirmation

Global read with regional edit is Read=Organisation plus Write=Business Unit in one Dataverse security role. Country is a team, not a business unit. Region means one of Americas, North West Europe, South East Europe, APAC.

Capability matrix

Ticks come from the real table permission matrix. A cell you change is outlined and listed above as a change request.

CapabilityAnonAuthCustomer contact (to confirm)
/
See own account overview
portal_surface:overview · R · Own account only (P8-Q3)
/open-questions
See the open questions
portal_surface:open-questions · R
/business-rules
See the business rules
portal_surface:business-rules · R

Rules that apply to everyone

Rules
  • Customer sees only their own data — stricter than internal.
  • No write path to CRM. Read-only integration; Power BI embeds for reporting.
  • No browser storage; tokens only; no hardcoded hex; Lucide icons 1.5px stroke; sentence case — the internal app's house rules apply.
  • Never invent answers to open questions — flag with a “pending confirmation” treatment, same discipline as the internal app.
  • A customer must see only their own account's data — stricter than the internal per-role model (P8-Q3).

Open questions

What the security workshops have not settled. Anyone may record a response; changing the wording of a question needs edit configuration.

  1. 1.

    P8-Q3 — A customer sees only their own account's data. What is the auth and row-level isolation approach on Power Pages?

  2. 2.

    P8-Q4 — How do customer users sign in — external identity / invitation flow on Power Pages?

  3. 3.

    P8-Q10 — Of the three management roles in the internal SAM app, which may change portal exposure directly and which may only propose? Is an approval step needed?