Accounts, organizations and roles
Understand the boundary between your identity, an organization and the services that organization owns.
Expected result
Every person receives the minimum role required for the correct organization.
Identity and tenant boundaries
Your account can belong to more than one organization. Data, domains and actions are always scoped to the selected organization.
Roles
- Owner manages the organization and sensitive settings.
- Security administrator configures services and policies.
- Operator investigates and executes approved procedures.
- Approver confirms high-impact actions.
- Analyst investigates without changing protection.
- Auditor reads evidence and history.
Use a separate approver for high-impact changes whenever possible.
Verification
- The member appears in the intended organization
- The role matches the approved responsibility