Skip to main content

Roles Needed to Access People

EmpowerID controls access to Person objects through Management Roles. Users must be assigned appropriate roles to work with people based on their organizational responsibilities and scope.

Management Role Types

Management Roles are prefixed by their function in EmpowerID:

  • UI — Grants access to specific UI elements in the EmpowerID Web interface
    • Example: UI-Person-Object-Administration grants access to Person management interfaces and workflows
  • VIS — Grants visibility to view specific objects in EmpowerID
    • Example: VIS-Person-MyLocations grants visibility to people in the same locations
  • ACT — Grants permission to manage (create, update, delete) specific objects in EmpowerID
    • Example: ACT-Person-Role-Assignment-All grants ability to assign and unassign roles for people
Role Combination

Most administrative tasks require a combination of UI, VIS, and ACT roles. For example, managing people in your location requires UI access to interfaces, VIS roles to see the people, and ACT roles to perform management actions.

Roles for Self-Service Profile Management

Users can view and edit their own profile information with the following roles:

View Roles for Self Profile Access
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Profile-Self-ServiceGrants access to user interfaces and workflows for managing own profile attributesFeature Set
VIS-Person-SelfGrants visibility to see own person (granted by default to all people)Visibility
ACT-Person-Profile-Self-ServiceGrants ability to edit own profile attributesActivity
Profile Self-ServiceGrants complete self-service profile management
Can be used in place of the three roles above

Contains:
• VIS-Person-Self
• ACT-Person-Profile-Self-Service
• UI-Person-Person-Profile-Self-Service
Role Bundle

Roles for Viewing People

To view people in EmpowerID, users need one of the following visibility roles based on the required scope:

View Visibility Roles for People
Management RoleAccess Granted by Management RoleRole Type
VIS-Person-SelfGrants access to see own person (granted by default to all people)Visibility
VIS-Person-MyDirectReportsGrants access to see direct reportsVisibility
VIS-Person-MyLocationsGrants access to see all people in the same locationsVisibility
VIS-Person-MyOrgGrants access to see all people in the same organizationsVisibility
VIS-Person-AllGrants access to see all people in the default organizationVisibility

Roles for Managing Profiles

To manage profile information for people, users need combinations of the following roles based on scope:

Roles needed by people to manage the profiles of their direct reports
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-Person-MyDirectReportsGrants visibility for all direct reportsVisibility
ACT-Person-Profile-Edit-DirectReportsGrants ability to edit profile attributes for direct reportsActivity
Roles needed by people to manage the profiles of people in their locations
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
ACT-Person-Profile-Edit-MyLocationsGrants ability to edit profile attributes for all people in their locationsActivity
Roles needed to manage the profile information of users belonging to the same organizations
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-Person-MyOrgGrants visibility for people in the same organizationsVisibility
ACT-Person-Profile-Edit-MyOrgGrants ability to edit profile attributes for all people in their organizationsActivity
Roles needed to manage the profile information of partners and customers
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-People-AllGrants visibility for all people in the systemVisibility
ACT-Person-Profile-Edit-CustomersGrants ability to edit profile attributes for all people below the Customers locationActivity
ACT-Person-Profile-Edit-PartnersGrants ability to edit profile attributes for all people below the Partners locationActivity
Roles needed to manage the profile information of all people
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-People-AllGrants visibility for all people in the systemVisibility
ACT-Person-Profile-Edit-AllGrants ability to edit profile attributes for all people in the systemActivity

Roles for Managing Management Role Assignments

To manage Management Role assignments for people, users need combinations of the following roles:

Roles needed to manage Management Role assignments for people in their locations
Management RoleAccess Granted by Management RoleRole Type
UI-Management-Role-Membership-ManagementGrants access to user interfaces and workflows for managing Management Role membershipFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
VIS-Management-Role-MyLocationsGrants visibility for all Management Roles in the same locationsVisibility
ACT-Management-Role-Membership-Management-MyLocationsGrants access to manage membership for Management Roles in their locationsActivity
Roles needed to manage Management Role assignments for people in their organizations
Management RoleAccess Granted by Management RoleRole Type
UI-Management-Role-Membership-ManagementGrants access to user interfaces and workflows for managing Management Role membershipFeature Set
VIS-Person-MyOrgGrants visibility for people in the same organizationsVisibility
VIS-Management-Role-MyOrgGrants visibility for all Management Roles in the same organizationsVisibility
ACT-Management-Role-Membership-Management-MyOrgGrants access to manage membership for Management Roles in their organizationActivity
Roles needed to manage Management Role assignments for partners
Management RoleAccess Granted by Management RoleRole Type
UI-Management-Role-Membership-ManagementGrants access to user interfaces and workflows for managing Management Role membershipFeature Set
VIS-Person-AllGrants visibility for all peopleVisibility
VIS-Management-Role-AllGrants visibility for all Management RolesVisibility
ACT-Management-Role-Membership-Management-PartnersGrants access to manage membership for Management Roles in or below the Partners locationActivity
Roles needed to manage Management Role assignments for all people
Management RoleAccess Granted by Management RoleRole Type
UI-Management-Role-Membership-ManagementGrants access to user interfaces and workflows for managing Management Role membershipFeature Set
VIS-Person-AllGrants visibility for all people in the systemVisibility
VIS-Management-Role-AllGrants visibility for all Management RolesVisibility
ACT-Management-Role-Membership-Management-AllGrants access to manage membership for all Management RolesActivity

Roles for Managing Business Role Assignments

To manage Business Role assignments for people, users need combinations of the following roles:

Roles needed to manage Business Role assignments for people in their locations
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Role-AssignmentGrants access to user interfaces and workflows for managing assignments of people to rolesFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
VIS-BusinessRole-MyLocationsGrants visibility for Business Roles in the same locations (required to see Business Roles in trees)Visibility
VIS-Location-MyLocationsAndBelowGrants visibility for the person's locations and below (required to see Locations in trees)Visibility
ACT-Business-Role-Assignment-MyLocationsGrants access to manage assignments of people to Business Roles in their locations and belowActivity
Roles needed to manage Business Role assignments for people in their organizations
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Role-AssignmentGrants access to user interfaces and workflows for managing assignments of people to rolesFeature Set
VIS-Person-MyOrgGrants visibility for people in the same organizationsVisibility
VIS-BusinessRole-MyOrgGrants visibility for Business Roles in the same organizationsVisibility
VIS-Location-All-Business-LocationsGrants visibility for all locations under All Business LocationsVisibility
VIS-Location-MyLocationsAndAboveGrants visibility for the person's locations and aboveVisibility
ACT-Business-Role-Assignment-MyOrgGrants access to manage assignments of people to Business Roles in their organizationsActivity
Roles needed to manage all Business Role assignments
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Role-AssignmentGrants access to user interfaces and workflows for managing assignments of people to rolesFeature Set
VIS-Person-AllGrants visibility for all people in the systemVisibility
VIS-BusinessRole-AllGrants visibility for all Business RolesVisibility
VIS-Location-AllGrants visibility for all locations in the systemVisibility
ACT-Business-Role-Assignment-AllGrants access to manage assignments of people to any Business RoleActivity

Roles for Managing Group Membership

To manage group membership for people, users need combinations of the following roles:

Roles needed to manage group membership for people in their locations
Management RoleAccess Granted by Management RoleRole Type
UI-Group-Membership-ManagementGrants access to user interfaces and workflows for group membership managementFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
VIS-Groups-Security-MyLocationGrants visibility for all Security groups in the same locationsVisibility
VIS-Groups-Distribution-MyLocationGrants visibility for all Distribution groups in the same locationsVisibility
VIS-Groups-Generic-MyLocationGrants visibility for all Generic groups in the same locationsVisibility
ACT-Group-Membership-Management-Distribution-MyLocationsGrants access to manage membership for all distribution groups in their locationsActivity
ACT-Group-Membership-Management-Generic-MyLocationsGrants access to manage membership for all generic groups in their locationsActivity
ACT-Group-Membership-Management-Security-MyLocationsGrants access to manage membership for all security groups in their locationsActivity
Roles needed to manage group membership for people in their organizations
Management RoleAccess Granted by Management RoleRole Type
UI-Group-Membership-ManagementGrants access to user interfaces and workflows for group membership managementFeature Set
VIS-Person-MyOrgGrants visibility for people in the same organizationsVisibility
VIS-Groups-Security-MyOrgGrants visibility for all Security groups in the same organizationsVisibility
VIS-Groups-Distribution-MyOrgGrants visibility for all Distribution groups in the same organizationsVisibility
VIS-Groups-Generic-MyOrgGrants visibility for all Generic groups in the same organizationsVisibility
ACT-Group-Membership-Management-Security-MyOrganizationsGrants access to manage membership for all security groups in their organizationsActivity
ACT-Group-Membership-Management-Distribution-MyOrganizationsGrants access to manage membership for all distribution groups in their organizationsActivity
ACT-Group-Membership-Management-Generic-MyOrganizationsGrants access to manage membership for all generic groups in their organizationsActivity
Roles needed to manage all group memberships
Management RoleAccess Granted by Management RoleRole Type
UI-Group-Membership-ManagementGrants access to user interfaces and workflows for group membership managementFeature Set
VIS-Person-AllGrants visibility for all people in the systemVisibility
VIS-Groups-AllGrants visibility for all groupsVisibility
ACT-Group-Membership-Management-All-GroupsGrants access to manage membership for all groupsActivity
Additional system-specific group management roles
Management RolePurposeRole Type
VIS-Groups-All-ADGrants visibility for all Active Directory groupsVisibility
VIS-Groups-All-AWSGrants visibility for all AWS groupsVisibility
VIS-Groups-All-AzureGrants visibility for all Azure groups in any tenantVisibility
VIS-Groups-All-IT-SystemsGrants visibility for all groups under All IT SystemsVisibility
VIS-Groups-All-O365Grants visibility for all Office 365 groupsVisibility
VIS-Groups-All-SAPGrants visibility for all SAP Roles and ProfilesVisibility
ACT-Group-Membership-Management-All-AD-GroupsGrants access to manage membership for all Active Directory groupsActivity
ACT-Group-Membership-Management-All-AWS-GroupsGrants access to manage membership for all AWS groupsActivity
ACT-Group-Membership-Management-All-IT-SystemsGrants access to manage membership for all groups under All IT SystemsActivity
ACT-Group-Membership-Management-All-O365-GroupsGrants access to manage membership for all Office 365 groupsActivity
ACT-Group-Membership-Management-All-SAP-GroupsGrants access to manage membership for all SAP Roles and ProfilesActivity

Roles for Creating Person Objects

To create new Person objects, users need combinations of the following roles:

Roles needed to create new people in their locations
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Object-CreateGrants access to user interfaces and workflows to create Person objectsFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
VIS-BusinessRole-MyLocationsGrants visibility for Business Roles in the same locations (all people require a Business Role)Visibility
VIS-Location-MyLocationsAndBelowGrants visibility for the person's locations and below (all people require a location)Visibility
ACT-Business-Role-Assignment-MyLocationsGrants access to assign people to Business Roles in their locations and belowActivity
Additionally, if assigning Management Roles during creation:
VIS-Management-Role-MyLocationsGrants visibility for Management Roles in the same locationsVisibility
ACT-Management-Role-Membership-Management-MyLocationsGrants access to manage membership for Management Roles in the same locationsActivity
Roles needed to create new people in any location
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Object-CreateGrants access to user interfaces and workflows to create Person objectsFeature Set
VIS-Person-AllGrants visibility for all people in the systemVisibility
VIS-BusinessRole-AllGrants visibility for all Business RolesVisibility
VIS-Location-AllGrants visibility for all locations in the systemVisibility
ACT-Business-Role-Assignment-AllGrants access to assign people to any Business RoleActivity
Additionally, if assigning Management Roles during creation:
VIS-Management-Role-AllGrants visibility for all Management RolesVisibility
ACT-Management-Role-Membership-Management-AllGrants access to manage membership for all Management RolesActivity

Roles for Person Administration

To perform comprehensive administrative actions (create, update, delete, restore), users need combinations of the following roles:

Roles needed to administer people in their locations
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Object-AdministrationGrants access to user interfaces and workflows for comprehensive person object managementFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
ACT-Person-Object-Administration-MyLocationsGrants access to create, update, and delete people in the same locationsActivity
Roles needed to administer people in their organizations
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Object-AdministrationGrants access to user interfaces and workflows for comprehensive person object managementFeature Set
VIS-Person-MyOrgGrants visibility for all people in the same organizationsVisibility
ACT-Person-Object-Administration-MyOrgGrants access to create, update, and delete people in the same organizationsActivity
Roles needed to administer partners and customers
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Object-AdministrationGrants access to user interfaces and workflows for comprehensive person object managementFeature Set
VIS-Person-AllGrants visibility for all peopleVisibility
ACT-Person-Object-Administration-PartnersGrants access to create, update, and delete all people below the Partners locationActivity
ACT-Person-Object-Administration-CustomersGrants access to create, update, and delete all people below the Customers locationActivity
Roles needed to administer all people
Management RoleAccess Granted by Management RoleRole Type
UI-Person-Object-AdministrationGrants access to user interfaces and workflows for comprehensive person object managementFeature Set
VIS-Person-AllGrants visibility for all peopleVisibility
ACT-Person-Object-Administration-AllGrants access to create, update, and delete all peopleActivity
note

For complete role details including specific workflow access, page controls, and web service access, expand each section above. The UI-Person-Object-Administration role provides the most comprehensive access for person management tasks.