Permissions to the menu item, with an audit trail behind every change.
Define a role once and every module honours it — so a developer sees their own scorecard while a delivery head sees the whole portfolio.
What is role based access control?
Role based access control, or RBAC, grants permissions to roles rather than individuals, then assigns people to roles. In Goalz a role carries menu-level permissions, so defining it once controls exactly which screens and records every holder of that role can reach. Permission and approval changes are recorded in an audit trail.
Governance that does not need a consultant.
Permissions at the level people actually worry about.
Coarse roles force a choice between too much access and constant exception requests. Menu-level permissions let you say yes to sprint planning and no to compensation in the same role.
One screen, the right slice of data.
Scope is part of the role, so you maintain one set of screens rather than separate self-service and manager views. A developer opens their scorecard; a delivery head opens the portfolio.
Every consequential action has a name on it.
Approving hours, moderating a figure, rating a ticket, changing a role — each is recorded with who did it and when, which is what turns a productivity number into something defensible.
Against per-tool permissions
Five tools mean five permission models, five offboarding checklists and five places a departed employee might still have access.
| Capability | Goalz | Separate tools | Shared logins |
|---|---|---|---|
| Single role across delivery, HR and leave | One role | One per tool | None |
| Menu-level permission granularity | Per menu item | Varies by tool | Not possible |
| Data scoping on the same screens | Built in | Separate portals | Everyone sees all |
| Offboarding revokes everything | One action | A checklist per tool | Password rotation |
| Audit trail of approvals | Actor and timestamp | Partial | Untraceable |
| Custom roles without a consultant | Self-serve | Varies | N/A |
| Passes an enterprise security review | Designed for it | Multiple reviews | Fails |
One role, honoured by all five modules.
Access control is not a module bolted on the side. It is the layer every other screen in Goalz reads before it renders.
Questions security reviews ask
Bring your org chart to the call.
We will map it to roles live and show you exactly what each person would and would not be able to see.