Resources
Templates & tools

RBAC role matrix: named-user, least-privilege access

Five roles with per-role landing pages and per-scope restriction — the access model that keeps external surveyors to their own batch.

5 min readUpdated June 2026

Access is named-user and least-privilege: no shared accounts, every action attributed, and external surveyors restricted to only the properties assigned to them. Each role lands on the area relevant to its job and is guarded from the rest.

The role matrix

RoleLands onCanScope / cannot
System administratorAdminManage users and roles; see the role matrixGoverns access; not a field capture role
Survey managerManageAssign survey batches, pre-load packs, monitor syncCannot accept their own surveys through QA
Internal surveyorSurveysCapture assigned surveys, photos, issues offlineSees only assigned properties
External supplier surveyorSurveysCapture assigned surveys offlineRestricted to an allow-list of assigned UPRNs only — never the wider portfolio
QA reviewerQAAccept / reject submitted surveys with commentsRead-only on capture; decisions are audited

The principles behind it

  • Named users, not shared logins — every capture, photo, QA decision and sync event is attributed.
  • Least privilege — each role sees only the lanes its job requires; wrong-role deep links are blocked.
  • Per-scope restriction — external surveyors are scoped to an explicit UPRN allow-list.
  • Offline identity — sign-in works from a cached identity so field work continues with no signal.
  • SSO/MFA-ready — built to wire into single sign-on, multi-factor auth and remote revocation for production.

Maker-checker by design

The QA reviewer role is the maker-checker gate: a survey only updates the live record after an independent reviewer accepts it — the same shape that generalises to delegated-partner assurance.

Sources & further reading

  1. 1. Data protection by design and default Information Commissioner's Office
  2. 2. Access control guidance National Cyber Security Centre

Turn the guidance into evidence

See how ClearView AMS captures the data behind every obligation — offline, evidence-led, and reconciled end to end.