Skip to main content
UI Coach Logo
Advanced

Enterprise Role Builder

Design an administrator workflow for composing a least-privilege role from permissions, conditions, and resource scope.

Desktop web4 hours plus

The brief

Understand the problem

Background

Enterprise permissions grow across products, resources, and actions. Broad role templates are convenient but can grant hidden capabilities through dependencies or inherited access.

User context

Administrator Tessa needs a billing analyst role that can view invoices and export monthly summaries for one region, but cannot change payment methods or inspect customer records.

Product problem

Administrators need to understand effective access and permission dependencies before assigning a custom role at scale.

Objective

Create role setup, permission composition, effective-access simulation, and publication for a scoped enterprise role.

What to design

Define the experience

Required experience

  • Define role purpose and resource scope
  • Add permissions from tasks or individual actions
  • Test effective access for representative users
  • Publish the role and review affected assignments

Screens and states

  • Role setup
  • Permission builder
  • Effective-access simulator
  • Publish review

Core user flow

Follow the critical path

  1. 01

    Tessa names the billing analyst role and selects one region

  2. 02

    She adds invoice read and summary export tasks

  3. 03

    The simulator reveals that one export permission also exposes customer email addresses

  4. 04

    She selects a redacted export alternative and publishes to a pilot group

Product rules

Requirements and constraints

Requirements

  • Organize permissions by user task while retaining action-level detail
  • Show inherited, dependent, conflicting, and conditionally granted access
  • Simulate effective access without changing production assignments
  • Summarize newly granted and removed capabilities before publication

Constraints

  • Protected system roles cannot be edited
  • Privilege escalation paths must be blocked
  • Publication requires an authorized reviewer when sensitive permissions are included

Reality check

States worth considering

A permission is deprecated
Two conditions conflict
An assigned user belongs to several groups
Removing access breaks an automated process

Ready-to-use content

Mock data

Use this content to test hierarchy and realistic data states. You can expand it when the concept needs more depth.

Billing permissions

  • View invoices
  • Export redacted summary
  • Edit payment method
  • View customer contact details

Scope conditions

  • Region equals Southeast Asia
  • Account status is active
  • Export rows limited to 50,000

Finish line

What to deliver

  • Four desktop screens with effective-access and conflict states

Optional direction

Visual resources

Use these as a starting constraint if you want one. They are not part of the required solution.

Font pairing
Open SansLibre Baskerville

Open Sans & Libre Baskerville

Clear interface writing gives people the confidence to understand what changed and decide what to do next.

Icons
Illustrations

Keep practicing

Advanced
Enterprise

Multi-Team Admin Platform

Design an organization administration system for teams, inherited permissions, shared billing, and auditable access changes.

Desktop web4 hours plus
Information ArchitectureDesign Systems
Advanced
Enterprise

Auditable Admin Data Export

Design an administrator export flow that scopes sensitive records, estimates impact, and controls secure delivery.

Desktop web4 hours plus
FormsTrust and Safety
Advanced
Enterprise

Data Retention Policy Builder

Design a governance tool for defining how long each data class is kept, archived, reviewed, and deleted across regions.

Desktop web4 hours plus
Information ArchitectureTrust and Safety
Advanced
Enterprise

Delegate a Sensitive Task to a Virtual Assistant

Design a remote-assistance workspace that defines scope, grants minimum access, and records completion without exposing an entire business account.

Desktop web4 hours plus
Trust and SafetyInformation Architecture
Advanced
Enterprise

Multi-Organization Workspace Switcher

Design a workspace switcher that makes organization, role, environment, and unsaved work clear before context changes.

Desktop web2 to 4 hours
NavigationInformation Architecture
Advanced
Enterprise

Bulk User Offboarding

Design a protected administrator flow for removing many departing users while transferring ownership and preserving required records.

Desktop web4 hours plus
Dashboard DesignTrust and Safety