A municipal IRM rollout spans Policy and Compliance, Risk, and Audit. How should roles and groups be patterned?
Select an answer to reveal the explanation.
Short Explanation
Least privilege is like city badge access: finance gets the vault, parks gets the greenhouse—not master keys for everyone. Common GRC role patterns still carve access by job, even when the apps share a platform. Admin-for-all is the opposite of that design.
Full Explanation
IRM applications share common role and group patterns so implementers can assign persona-appropriate access across Policy and Compliance, Risk, and Audit. Least privilege remains required: users should receive only the roles needed for their duties, not blanket admin. Relying solely on ITIL roles or letting auditors rewrite risk scores collapses those shared, least-privilege patterns.