Roles & Global Responsibility Matrix¶
Status: FROZEN — Foundation v1.0
Roles are permission bundles, not hard-coded authorization checks. Tenants may receive configurable roles later, but the following personas define the baseline.
Baseline roles¶
| Role | Responsibility |
|---|---|
| Platform Administrator | Operates SaaS platform, tenants, plans, vertical catalog, incidents and platform-level policy. |
| Platform Support | Support/diagnostics with tightly audited delegated access. |
| Tenant Owner | Commercial/account owner; subscription/modules, billing, domains, top-level configuration and team ownership. |
| Tenant Administrator | Day-to-day organization/business-unit/site administration. |
| Business Manager | Manages offerings, resources, availability and bookings for assigned business units. |
| Content Editor | Pages, content, media, SEO and Managed Site composition subject to permissions. |
| Translator / Locale Editor | Optional permission bundle for translating/approving content in assigned locales; not necessarily a hard-coded platform role. |
| Marketing Manager | Campaigns, attribution, catalogs and tenant-connected advertising accounts/campaigns. |
| Finance Manager | Tenant payment account configuration, payments, refunds, invoices and financial reporting subject to permission. |
| Operations Staff | Fulfillment/reservation/service operations with limited administrative access. |
| Customer | Registered or linked tenant end customer/guest. |
| Anonymous Visitor | Unauthenticated public-site user. |
| External System | Authorized API client/webhook consumer/provider. |
Customer visibility rule¶
Customer identity is tenant-wide, but role/membership scopes may limit staff to Business Units, Sites or Locations. Tenant-wide identity therefore does not imply tenant-wide staff visibility.
Global RACI¶
Legend: R responsible, A accountable, C consulted, I informed, — no baseline responsibility.
| Activity | Platform Admin | Tenant Owner | Tenant Admin | Business Manager | Content Editor | Marketing | Finance | Ops | Customer |
|---|---|---|---|---|---|---|---|---|---|
| Create/suspend tenant | A/R | I | — | — | — | — | — | — | — |
| Accept/change commercial plan | C | A/R | I | — | — | — | C | — | — |
| Purchase/enable billable capability | I | A/R | C | C | — | — | C | I | — |
| Configure business units/primary vertical | I | A | R | C | — | — | — | C | — |
| Associate locations/business units | I | A | R | C | — | — | — | C | — |
| Manage offerings/resources | — | A | C | R | — | — | — | C | — |
| Configure Managed Site | — | A | C | — | R | C | — | — | I |
| Configure locales / translation workflow | C | A | R | — | R | C | — | — | I |
| Connect advertising accounts | — | A | C | — | — | R | C | — | — |
| Connect payment accounts | — | A | C | — | — | — | R | C | — |
| Manage bookings | — | I | A | C | — | — | C | R | C |
| Issue refund | — | A | C | — | — | — | R | C | I |
| Change plan entitlement definitions | A/R | C | I | — | — | — | — | — | — |
| Platform incident response | A/R | I | I | I | I | I | I | I | I |