Skip to main content

Access to People (Management Roles Reference)

This reference provides comprehensive information about Management Roles required to work with Person objects in EmpowerID. Use this guide to identify which role combinations grant specific permissions and assign appropriate roles based on users' organizational responsibilities.

Role Structure Overview

Management Roles for Person objects follow a consistent three-part structure:

UI Roles grant access to user interfaces and workflows for specific tasks. These roles control which pages and workflows users can access in EmpowerID.

VIS Roles grant visibility to see Person objects. Visibility can be scoped by relationship (self, direct reports) or organizational level (location, organization, all people).

ACT Roles grant permission to perform actions on Person objects. These roles control what users can actually do with the people they can see.

All three role types are required to work together to provide complete administrative access

Most administrative tasks require a combination of all three role types to function properly. For example, to edit profiles for people in your location, you need:

  • UI role to access the profile editing interface
  • VIS role to see people in your location
  • ACT role to perform edit actions

Example: Managing Profiles in Your Location

This example demonstrates how the three role types work together:

Management RolePurposeRole Type
UI-Person-Profile-EditGrants access to profile editing interfaces and workflowsFeature Set
VIS-Person-MyLocationsGrants visibility to see people in your locationsVisibility
ACT-Person-Profile-Edit-MyLocationsGrants permission to edit profile attributesActivity

All three roles are required to manage profiles. The sections below follow this same pattern for different tasks and scopes.

Using This Reference

Use Ctrl+F (or Cmd+F on Mac) to search for specific role names, or scan the section headings below to find role combinations organized by task type. Each section provides complete role information for specific administrative scenarios.

Detailed Role Information

Self-Service Profile Management

Users managing their own profile information need the following roles:

Management RoleAccess GrantedRole Type
UI-Person-Profile-Self-ServiceGrants access to user interfaces and workflows for managing own profile attributesFeature Set
VIS-Person-SelfGrants visibility to see own person (granted by default to all people)Visibility
ACT-Person-Profile-Self-ServiceGrants ability to edit own profile attributesActivity
Profile Self-ServiceRole bundle containing all three roles above
Use this bundle to grant complete self-service profile management
Role Bundle

Viewing People

To view people in EmpowerID, users need one of the following visibility roles based on the required scope:

Management RoleAccess GrantedRole Type
VIS-Person-SelfGrants access to see own person (granted by default to all people)Visibility
VIS-Person-MyDirectReportsGrants access to see direct reportsVisibility
VIS-Person-MyLocationsGrants access to see all people in the same locationsVisibility
VIS-Person-MyOrgGrants access to see all people in the same organizationsVisibility
VIS-Person-AllGrants access to see all people in the default organizationVisibility

Managing Profile Information

Direct Reports

Managers editing their direct reports' profile information need:

Management RoleAccess GrantedRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-Person-MyDirectReportsGrants visibility for all direct reportsVisibility
ACT-Person-Profile-Edit-DirectReportsGrants ability to edit profile attributes for direct reportsActivity

Location-Based Access

Users managing profiles for people in their locations need:

Management RoleAccess GrantedRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
ACT-Person-Profile-Edit-MyLocationsGrants ability to edit profile attributes for all people in their locationsActivity

Organization-Based Access

Users managing profiles for people in their organizations need:

Management RoleAccess GrantedRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-Person-MyOrgGrants visibility for people in the same organizationsVisibility
ACT-Person-Profile-Edit-MyOrgGrants ability to edit profile attributes for all people in their organizationsActivity

Partners and Customers

Users managing profiles for partners and customers need:

Management RoleAccess GrantedRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-People-AllGrants visibility for all people in the systemVisibility
ACT-Person-Profile-Edit-CustomersGrants ability to edit profile attributes for all people below the Customers locationActivity
ACT-Person-Profile-Edit-PartnersGrants ability to edit profile attributes for all people below the Partners locationActivity

All People

Users managing profiles for all people need:

Management RoleAccess GrantedRole Type
UI-Person-Profile-EditGrants access to user interfaces and workflows for editing people's profile attributesFeature Set
VIS-People-AllGrants visibility for all people in the systemVisibility
ACT-Person-Profile-Edit-AllGrants ability to edit profile attributes for all people in the systemActivity

Managing Management Role Assignments

Location-Based Access

Users managing Management Role assignments for people in their locations need:

Management RoleAccess GrantedRole Type
UI-Management-Role-Membership-ManagementGrants access to user interfaces and workflows for managing Management Role membershipFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
VIS-Management-Role-MyLocationsGrants visibility for all Management Roles in the same locationsVisibility
ACT-Management-Role-Membership-Management-MyLocationsGrants access to manage membership for Management Roles in their locationsActivity

Organization-Based Access

Users managing Management Role assignments for people in their organizations need:

Management RoleAccess GrantedRole Type
UI-Management-Role-Membership-ManagementGrants access to user interfaces and workflows for managing Management Role membershipFeature Set
VIS-Person-MyOrgGrants visibility for people in the same organizationsVisibility
VIS-Management-Role-MyOrgGrants visibility for all Management Roles in the same organizationsVisibility
ACT-Management-Role-Membership-Management-MyOrgGrants access to manage membership for Management Roles in their organizationActivity

Partners

Users managing Management Role assignments for partners need:

Management RoleAccess GrantedRole Type
UI-Management-Role-Membership-ManagementGrants access to user interfaces and workflows for managing Management Role membershipFeature Set
VIS-Person-AllGrants visibility for all peopleVisibility
VIS-Management-Role-AllGrants visibility for all Management RolesVisibility
ACT-Management-Role-Membership-Management-PartnersGrants access to manage membership for Management Roles in or below the Partners locationActivity

All People

Users managing Management Role assignments for all people need:

Management RoleAccess GrantedRole Type
UI-Management-Role-Membership-ManagementGrants access to user interfaces and workflows for managing Management Role membershipFeature Set
VIS-Person-AllGrants visibility for all people in the systemVisibility
VIS-Management-Role-AllGrants visibility for all Management RolesVisibility
ACT-Management-Role-Membership-Management-AllGrants access to manage membership for all Management RolesActivity

Managing Business Role Assignments

Location-Based Access

Users managing Business Role assignments for people in their locations need:

Management RoleAccess GrantedRole Type
UI-Person-Role-AssignmentGrants access to user interfaces and workflows for managing assignments of people to rolesFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
VIS-BusinessRole-MyLocationsGrants visibility for Business Roles in the same locations (required to see Business Roles in trees)Visibility
VIS-Location-MyLocationsAndBelowGrants visibility for the person's locations and below (required to see Locations in trees)Visibility
ACT-Business-Role-Assignment-MyLocationsGrants access to manage assignments of people to Business Roles in their locations and belowActivity

Organization-Based Access

Users managing Business Role assignments for people in their organizations need:

Management RoleAccess GrantedRole Type
UI-Person-Role-AssignmentGrants access to user interfaces and workflows for managing assignments of people to rolesFeature Set
VIS-Person-MyOrgGrants visibility for people in the same organizationsVisibility
VIS-BusinessRole-MyOrgGrants visibility for Business Roles in the same organizationsVisibility
VIS-Location-All-Business-LocationsGrants visibility for all locations under All Business LocationsVisibility
VIS-Location-MyLocationsAndAboveGrants visibility for the person's locations and aboveVisibility
ACT-Business-Role-Assignment-MyOrgGrants access to manage assignments of people to Business Roles in their organizationsActivity

All People

Users managing all Business Role assignments need:

Management RoleAccess GrantedRole Type
UI-Person-Role-AssignmentGrants access to user interfaces and workflows for managing assignments of people to rolesFeature Set
VIS-Person-AllGrants visibility for all people in the systemVisibility
VIS-BusinessRole-AllGrants visibility for all Business RolesVisibility
VIS-Location-AllGrants visibility for all locations in the systemVisibility
ACT-Business-Role-Assignment-AllGrants access to manage assignments of people to any Business RoleActivity

Managing Group Membership

Location-Based Access

Users managing group membership for people in their locations need:

Management RoleAccess GrantedRole Type
UI-Group-Membership-ManagementGrants access to user interfaces and workflows for group membership managementFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
VIS-Groups-Security-MyLocationGrants visibility for all Security groups in the same locationsVisibility
VIS-Groups-Distribution-MyLocationGrants visibility for all Distribution groups in the same locationsVisibility
VIS-Groups-Generic-MyLocationGrants visibility for all Generic groups in the same locationsVisibility
ACT-Group-Membership-Management-Distribution-MyLocationsGrants access to manage membership for all distribution groups in their locationsActivity
ACT-Group-Membership-Management-Generic-MyLocationsGrants access to manage membership for all generic groups in their locationsActivity
ACT-Group-Membership-Management-Security-MyLocationsGrants access to manage membership for all security groups in their locationsActivity

Organization-Based Access

Users managing group membership for people in their organizations need:

Management RoleAccess GrantedRole Type
UI-Group-Membership-ManagementGrants access to user interfaces and workflows for group membership managementFeature Set
VIS-Person-MyOrgGrants visibility for people in the same organizationsVisibility
VIS-Groups-Security-MyOrgGrants visibility for all Security groups in the same organizationsVisibility
VIS-Groups-Distribution-MyOrgGrants visibility for all Distribution groups in the same organizationsVisibility
VIS-Groups-Generic-MyOrgGrants visibility for all Generic groups in the same organizationsVisibility
ACT-Group-Membership-Management-Security-MyOrganizationsGrants access to manage membership for all security groups in their organizationsActivity
ACT-Group-Membership-Management-Distribution-MyOrganizationsGrants access to manage membership for all distribution groups in their organizationsActivity
ACT-Group-Membership-Management-Generic-MyOrganizationsGrants access to manage membership for all generic groups in their organizationsActivity

All People

Users managing all group memberships need:

Management RoleAccess GrantedRole Type
UI-Group-Membership-ManagementGrants access to user interfaces and workflows for group membership managementFeature Set
VIS-Person-AllGrants visibility for all people in the systemVisibility
VIS-Groups-AllGrants visibility for all groupsVisibility
ACT-Group-Membership-Management-All-GroupsGrants access to manage membership for all groupsActivity

System-Specific Group Management

Additional roles for managing groups in specific systems:

Management RolePurposeRole Type
VIS-Groups-All-ADGrants visibility for all Active Directory groupsVisibility
VIS-Groups-All-AWSGrants visibility for all AWS groupsVisibility
VIS-Groups-All-AzureGrants visibility for all Azure groups in any tenantVisibility
VIS-Groups-All-IT-SystemsGrants visibility for all groups under All IT SystemsVisibility
VIS-Groups-All-O365Grants visibility for all Office 365 groupsVisibility
VIS-Groups-All-SAPGrants visibility for all SAP Roles and ProfilesVisibility
ACT-Group-Membership-Management-All-AD-GroupsGrants access to manage membership for all Active Directory groupsActivity
ACT-Group-Membership-Management-All-AWS-GroupsGrants access to manage membership for all AWS groupsActivity
ACT-Group-Membership-Management-All-IT-SystemsGrants access to manage membership for all groups under All IT SystemsActivity
ACT-Group-Membership-Management-All-O365-GroupsGrants access to manage membership for all Office 365 groupsActivity
ACT-Group-Membership-Management-All-SAP-GroupsGrants access to manage membership for all SAP Roles and ProfilesActivity

Creating Person Objects

Location-Based Access

Users creating new people in their locations need:

Management RoleAccess GrantedRole Type
UI-Person-Object-CreateGrants access to user interfaces and workflows to create Person objectsFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
VIS-BusinessRole-MyLocationsGrants visibility for Business Roles in the same locations (all people require a Business Role)Visibility
VIS-Location-MyLocationsAndBelowGrants visibility for the person's locations and below (all people require a location)Visibility
ACT-Business-Role-Assignment-MyLocationsGrants access to assign people to Business Roles in their locations and belowActivity

Additionally, if assigning Management Roles during creation:

Management RoleAccess GrantedRole Type
VIS-Management-Role-MyLocationsGrants visibility for Management Roles in the same locationsVisibility
ACT-Management-Role-Membership-Management-MyLocationsGrants access to manage membership for Management Roles in the same locationsActivity

All Locations

Users creating new people in any location need:

Management RoleAccess GrantedRole Type
UI-Person-Object-CreateGrants access to user interfaces and workflows to create Person objectsFeature Set
VIS-Person-AllGrants visibility for all people in the systemVisibility
VIS-BusinessRole-AllGrants visibility for all Business RolesVisibility
VIS-Location-AllGrants visibility for all locations in the systemVisibility
ACT-Business-Role-Assignment-AllGrants access to assign people to any Business RoleActivity

Additionally, if assigning Management Roles during creation:

Management RoleAccess GrantedRole Type
VIS-Management-Role-AllGrants visibility for all Management RolesVisibility
ACT-Management-Role-Membership-Management-AllGrants access to manage membership for all Management RolesActivity

Person Administration (Full Access)

Person administration roles provide comprehensive access to create, update, delete, and restore Person objects.

Location-Based Access

Users administering people in their locations need:

Management RoleAccess GrantedRole Type
UI-Person-Object-AdministrationGrants access to user interfaces and workflows for comprehensive person object managementFeature Set
VIS-Person-MyLocationsGrants visibility for all people in the same locationsVisibility
ACT-Person-Object-Administration-MyLocationsGrants access to create, update, and delete people in the same locationsActivity

Organization-Based Access

Users administering people in their organizations need:

Management RoleAccess GrantedRole Type
UI-Person-Object-AdministrationGrants access to user interfaces and workflows for comprehensive person object managementFeature Set
VIS-Person-MyOrgGrants visibility for all people in the same organizationsVisibility
ACT-Person-Object-Administration-MyOrgGrants access to create, update, and delete people in the same organizationsActivity

Partners and Customers

Users administering partners and customers need:

Management RoleAccess GrantedRole Type
UI-Person-Object-AdministrationGrants access to user interfaces and workflows for comprehensive person object managementFeature Set
VIS-Person-AllGrants visibility for all peopleVisibility
ACT-Person-Object-Administration-PartnersGrants access to create, update, and delete all people below the Partners locationActivity
ACT-Person-Object-Administration-CustomersGrants access to create, update, and delete all people below the Customers locationActivity

All People

Users administering all people need:

Management RoleAccess GrantedRole Type
UI-Person-Object-AdministrationGrants access to user interfaces and workflows for comprehensive person object managementFeature Set
VIS-Person-AllGrants visibility for all peopleVisibility
ACT-Person-Object-Administration-AllGrants access to create, update, and delete all peopleActivity
Most Comprehensive Access

The UI-Person-Object-Administration role provides the most comprehensive access for person management tasks, including access to all person-related workflows, page controls, and web service operations.