Scoped data access
Organisation and library access checks govern which service designs and submissions a team member can work with. Roles distinguish design, deployment and live-data responsibilities, while service authentication and sharing settings control access within the respondent journey.
Apply permissions around the tasks people need to perform. For a review or multi-party service, test access using the intended participant and reviewer roles, including attempts to open records outside their scope.
- Assign the smallest role that supports the person’s responsibilities.
- Review service sharing and reviewer access as part of the journey design.
- Keep QA testing separate from live submission access.
