Viewing as Project lead · Reads globally · edits globally · approves nowhere · country teams: United Kingdom
Roles & permissions
A map of every persona in EPMS and what each one may do. Switch on Edit configuration to change what a persona should be allowed to do — edits are saved for everyone and listed as change requests until they are built into the application. This page is a review device; real enforcement is Dataverse security roles, business units and column security.
Project lead
Runs delivery and owns the project record end to end. Reads and edits globally and may raise a request — client-mandated, confirmed by Alex 3 Sep 2026. The in-app Performance page exists instead of reporting.
Allowed
Decide deliverables, machines and equipment with the project engineers
Log a change and re-issue the affected proposals
Raise actions with assignee, due date and priority
Read and edit projects globally
Raise a request
See the in-app Performance page instead of Power BI
Not allowed
Record any commercial approval
Reach Power BI reporting — licence cost, not distrust
What each persona may read, edit and approve. Three separate scopes, never one depth: read is routinely wider than edit.
Persona
Level
Read
Edit
Approve
Reporting
Approval team – Route
1
Global
—
Global
Performance page
Approval team – Resources (Tooling led / Solution led)
2
Global
Region
Global
Approval team – Resources (Application Engineering)
2
Global
Region
Global
Project lead
3
Global
Global
—
Performance page
Commercial lead
3
Region
Region
—
Performance page
Project engineer / delivery
4
Global
Global
—
Performance page
View only
5
Global
—
—
Performance page
Platform administrator
6
Global
Global
Global
Performance page
Suggestion approver
external
Global
—
—
—
Global read with regional edit is Read=Organisation plus Write=Business Unit in one Dataverse security role. Country is a team, not a business unit, so country scoping is expressed as team ownership.
Action matrix
Action
Effect
Approval team – Route
Approval team – Resources (Tooling led / Solution led)
Approval team – Resources (Application Engineering)
Project lead
Commercial lead
Project engineer / delivery
View only
Platform administrator
Suggestion approver
Raise a requestRequests
Nothing → Submitted
Decide the route, commercial lead and recommended technical lead poolApprovals
To be reviewed – route → To be reviewed – resources – Solva / – Application Engineering
Decide deliverables, machines and equipmentApprovals
Assessed → Scoped
Decide resource and assign the project leaderApprovals
To be reviewed – resources → Reviewed, project created
Ask for more info on the allocation approvalApprovals
Stays a request — nothing allocated, follow-up owner named
Send the request back to salesApprovals
Any review stage → Reviewed (back to sales)
Read records outside the edit scopeRegisters and records
Row visible, read-only, marked with a lock
Create the project from the requestProjects
Routed → Project created
Issue or re-issue a proposalProject → offer
Draft → Issued
Log a change and up-issue the proposalsProject → negotiation
Issued → Re-issued
Record the signed agreementProject → agreement
Offered → Signed
Send a document for signatureProject → agreement
Drafted → Out for signature
Assign a person or equipmentResources
Unassigned → Assigned
Direct resource in another regionResources
Resource in one region → Booked on another region's project
Raise an actionAction log
Nothing → Open action
Complete an actionAction log
Open → Complete
Book pre-sales time on a proposalProject → offer
No time → Booked (pre-sales)
Book project time after signatureTime
No time → Booked (delivery)
Read cost and charge rateTime, financials, reporting
Column-secured columns returned
Upload a technical fileProject → technical documents
Attempt audited, permitted or refused
Close the projectProject record
Delivering → Closed
Administer choice lists and rulesAdministration
Reference data changed
The administrator seat holds every action by design; every administrative change is logged.
Rules that apply to everyone
Personas are a review device in this prototype. Real enforcement is Dataverse security roles, business units, teams and column security.
Scope is three separate things, never one depth: what you may read, what you may edit and what you may approve. Read is routinely wider than edit.
Edit at your own level, read one level up. A project lead edits in their country and reads across the region.
Region is a child business unit of the SECO root. Country is a team owned by a region, not a business unit — country scoping is expressed as team ownership.
Global read with regional edit is a single Dataverse security role holding Read = Organisation and Write = Business Unit. It is not two roles.
Approvals sit with three flat teams, none of which has a leader: Approval team – Route takes the route decision, then the request goes to Approval team – Resources (Tooling led / Solution led) or Approval team – Resources (Application Engineering), whichever the route names. No other persona records an approval.
The allocation approval has five options, not four: the four routes, plus 'More info needed'. More info needed allocates nothing, moves no stage, and must name an Approval Team member to follow it up.
Approvals go to a flat team, never to a named individual, and every team must hold at least two people. No individual takes a step out of the team — the team owns it throughout.
If a team leaves a step undecided, it escalates one level up. Absence is covered by the team; silence is covered by escalation.
Strategic accounts are reviewed by the global Approval team – Route. Standard accounts are reviewed by the country channel of the same team.
Region and country govern visibility and approval. They do not govern who may be assigned: the resource pool is global and capacity belongs to the person, not the region.
Cost, charge rate and margin are a field security profile, not a role. A persona without that profile does not receive the columns on any form, view or export.
Reporting is scarce on cost grounds — Power BI licensing and utilisation. Two personas hold it, the two resources approval teams; everyone else internal gets the in-app Performance page.
Every upload attempt is audited with actor, record, verdict and reason, whether it was permitted or refused.
No persona can record two independent approvals on the same request.
Questions
Raised at the security workshop. Anyone may record a response; a question moves to Answered once it has one. The wording of the question itself only changes under Edit configuration.
1What are the real region names, and how many regions are there? The prototype assumes Europe and Americas as child business units of the SECO root.
2Which CRM teams already exist, and can EPMS reuse them for country scoping rather than creating a parallel set?
3Is cross-region read legally acceptable everywhere, or does any territory restrict it — works councils, export control, data residency?
4With the commercial approval step retired, who owns the commercial line on a request in each market — the commercial lead, or somebody else?
5What are the real names of the two resources approval teams, and does the Tooling led / Solution led split match how the business is organised?
6Who sits in each of the three approval teams by name, and is each large enough to cover every region and every absence?
7Does an approval team decide alone, or does it take the commercial and technical assessments as advice it must record?
8How long may an approval step sit undecided before it escalates, and to whom exactly?
9Which accounts are strategic, who maintains that flag, and does it live in the CRM or in EPMS?
10What is the name of the finance field security profile, and who administers membership of it?
11Finance is no longer a persona in EPMS, so who actually holds the cost and charge field security profile now — named individuals, a finance team, or an administrator-only profile?
Change requests
Every edit recorded on this page — matrix cells, scopes, persona wording and global rules — until it is built into the application. Marking one implemented closes it here and on the Business rules page.
Nothing outstanding — the saved configuration matches what the application enforces.