Enterprise · RBAC

Only give users access to what they need.

Roles should follow concrete responsibilities. Restrict access by function, store and team and make exceptions visible and periodically subject to reassessment.

Least privilege

Only give rights that are necessary for the daily task of the user or integration.

Store-scope

Prevent local teams from accessing configuration or data from other stores or brands.

Function separation

Separate analytics, merchandising, configuration and technical management where responsibilities demand that.