Goalz.Work
HomeUser & Access Control
User & Access Control

Permissions to the menu item, with an audit trail behind every change.

Define a role once and every module honours it — so a developer sees their own scorecard while a delivery head sees the whole portfolio.

Screenshot — Manage Roles or permission matrix

What is role based access control?

Role based access control, or RBAC, grants permissions to roles rather than individuals, then assigns people to roles. In Goalz a role carries menu-level permissions, so defining it once controls exactly which screens and records every holder of that role can reach. Permission and approval changes are recorded in an audit trail.

What's inside

Governance that does not need a consultant.

Custom roles
Build roles that match your job titles rather than bending your org to someone else’s presets.
Menu-level permissions
Grant or deny access screen by screen, so sprint planning and salary data are never the same decision.
Data scoping
The same screen shows one person their own record and a delivery head the whole portfolio.
User provisioning
Create a user against an employee record and a role; deactivation revokes every module at once.
Audit trail
Role edits, assignments, hour approvals and ratings recorded with actor and timestamp.
Approval authority
Who can approve hours, leave and client sign-off is a property of the role, not a side agreement.
Granularity

Permissions at the level people actually worry about.

Coarse roles force a choice between too much access and constant exception requests. Menu-level permissions let you say yes to sprint planning and no to compensation in the same role.

Allow or deny per individual menu item
Start from a default role and adjust, or build from scratch
Changes take effect across every module immediately
Screenshot — role permission matrix by menu
Scoping

One screen, the right slice of data.

Scope is part of the role, so you maintain one set of screens rather than separate self-service and manager views. A developer opens their scorecard; a delivery head opens the portfolio.

Own record, own team, own projects, or everything
Approval authority scoped the same way
No parallel employee portal to keep in step
Screenshot — same screen, two different scopes
Accountability

Every consequential action has a name on it.

Approving hours, moderating a figure, rating a ticket, changing a role — each is recorded with who did it and when, which is what turns a productivity number into something defensible.

Hour approvals and moderations recorded with the approver
Role and permission changes logged with timestamps
Historical data preserved when a user is deactivated
Screenshot — audit trail of approvals and role changes
Compared

Against per-tool permissions

Five tools mean five permission models, five offboarding checklists and five places a departed employee might still have access.

CapabilityGoalzSeparate toolsShared logins
Single role across delivery, HR and leaveOne roleOne per toolNone
Menu-level permission granularityPer menu itemVaries by toolNot possible
Data scoping on the same screensBuilt inSeparate portalsEveryone sees all
Offboarding revokes everythingOne actionA checklist per toolPassword rotation
Audit trail of approvalsActor and timestampPartialUntraceable
Custom roles without a consultantSelf-serveVariesN/A
Passes an enterprise security reviewDesigned for itMultiple reviewsFails
Works with

One role, honoured by all five modules.

Access control is not a module bolted on the side. It is the layer every other screen in Goalz reads before it renders.

FAQ

Questions security reviews ask

Role based access control, or RBAC, grants permissions to roles rather than individuals, then assigns people to roles. In Goalz a role carries menu-level permissions, so defining it once controls exactly which screens and records every holder of that role can reach.

Bring your org chart to the call.

We will map it to roles live and show you exactly what each person would and would not be able to see.