Technical access is not operational authority
A system administrator holds full technical write access yet holds no operational authority. They cannot approve a permit, release a work package, validate a critical control, remove a HOLD or authorize an exception. This separation is enforced in the decision model, not by hiding buttons.
Identity
Authenticated via enterprise IdP
Access model
RBAC for reachability
Authorization model
ABAC for decisions
Device
Registered device identity required for field decisions
Session
Session validity policy — enterprise configurable
Offline storage
Encrypted local package store (policy-defined)
Least privilege
Minimum data exposure per persona
Audit
Every decision written with authority basis
Authority roles
DecisionAuthority = Role × Area × Activity × Shift × RiskLevel × RegisterType × DelegationScope
AccountableProcess OwnerFunctional OwnerData OwnerData StewardRequestorReviewerApproverExecutorCustodianValidatorEscalation OwnerDelegate
Persona matrix — permission versus authority
No person is hard-coded as a permanent authority.
| Persona | Authority scope | System permission | Operational authority | Not exposed |
|---|---|---|---|---|
| Area Superintendent | Area 200 · Day A · up to High risk | Read all packages in area; write release decisions | Release work packageEscalate restrictionAccept conditional state | Individual health data; Commercial client correspondence |
| ES&H Supervisor | Area 200/300 · all shifts · fatal-risk activities | Read all ES&H objects; write verification records | Validate critical controlRaise STOPApprove JHA | Commercial data; Schedule baseline edits |
| Field Engineer | Area 200 · Day A | Compose packages; raise transactions | Request permitCompose preventive package | Approval actions; Delegation records |
| Crew Lead (Field Mode) | Assigned packages only | Offline package read; evidence capture | Capture evidenceRaise STOP | Commercial data; Other crews' competency records |
| Permit Authorizer | Area 200 · Day A · permits & work authorizations | Read work control objects | Approve permit within scope | Engineering release; Client release |
| Construction Manager | Project-wide assurance | Read all; no transactional write | EscalateAccept project-level risk within delegation | Individual health data |
| System Administrator | None — technical only | Full technical write access to records and configuration | NONE | All operational decisions: cannot approve, release, validate a control, remove a HOLD or authorize an exception |
Delegation register
If required authority is unavailable and no valid delegate exists: HOLD — Authorized Decision Authority Unavailable. There is no software bypass.
DLG-0031Area Superintendent acting as Permit Authorizer — WP-1009ACTIVE
Delegate ref
PER-2011
Area
Area 300
Activity
Hot Work
Register type
Permit / Work Authorization
Valid from
2026-08-29 18:00:00Z
Valid to
2026-08-31 06:00:00Z
Shift
Night B
Decision scope
Approve hot work permits up to High risk; excludes confined space and MV switching.