Roles, attributes and the roles × actions matrix
Lesson 1 of the module "Deciding who can do what" in the course "Design authentication and permissions for a product".
Lesson objective
By the end of this lesson, you will be able to build your product's roles × actions matrix, with the scope of each right (whole account, an area, their own items), choose between fixed roles, attributes and custom roles, and write the server-side enforcement rules (deny by default, least privilege).
Where it fits
Deciding who can do what
How do you design clear roles and permissions, and guarantee that no customer sees another's data?
Lessons in this module
- Roles, attributes and the roles × actions matrix (this lesson)
- Isolation between customers, invitations, audit and account deletion
What you will learn in the course
This lesson is part of the course Design authentication and permissions for a product
- Distinguish authentication, authorization and session, and specify session durations, sign-out and access revocation.
- Specify password rules and account recovery journeys following current recommendations (NIST SP 800-63B-4, CNIL, OWASP).
- Choose strong authentication factors (TOTP app, passkeys), plan their rollout and specify the fallback journeys.
- Specify delegated sign-in (OpenID Connect, social login) and enterprise SSO (SAML, OIDC, SCIM provisioning) for a B2B product.
- Design a permission model (roles, attributes, scope) as a roles × actions matrix, enforced on the server side according to least privilege.
- Specify isolation between customers, invitations, the audit log, support access and account deletion.
- Specify your product's complete sign-in journeys, with states and errors, and choose between building and using an authentication provider.
Related courses
- Git for PMs: ship as a team without putting production at riskAdvanced · ~3 hr 30 min
- Explain how a web product works, from browser to serverAll levels · ~2 hr 30 min
- Design and test an API integration as a PMJunior · ~3 hr