Department directors request visibility limited to their entities’ risks and controls. What access approach should the implementer use?
Select an answer to reveal the explanation.
Short Explanation
Directors need a window into their own street—not the master keys to rewire the whole city. Groups and roles scoped to their entities give the right visibility without spraying GRC admin everywhere. That is how access planning stays tidy.
Full Explanation
IRM access design uses platform groups and GRC roles, often with entity-oriented scoping, so leaders see risks and controls for their area without receiving administrative configuration rights. Sharing GRC admin for convenience undermines least privilege and model integrity. Scoped group/role design is the implementation-planning answer for departmental visibility.