6a

Permission grid

identity mapping (7a) executive dashboard (2a)

Two axes decide what a person sees: which fields their role may read, and how wide their scope reaches. The grid handles the first, the scope row above it handles the second, and “Preview as role” proves the result — it renders the real dashboard through that role's permissions, so nobody has to create a test agent to check that payroll is unreachable.

UNISON Administration
Search fields, roles, accounts
Administrator Alastair Boychuk AB
Preview as role
Renders the live dashboard through this role's permissions and scope. Read-only, nothing is logged against the agent.
Preview Dashboard as {{ previewRole }} · scope {{ previewScope }} · {{ previewDenied }} of 18 fields hidden
{{ t.label }}
{{ t.value }}
{{ t.note }}
———
Not visible to {{ previewRole }}. Field denied in {{ t.domain }}.
Ranking widgets, office comparisons and the restricted band are absent entirely at this scope — a denied field is never shown as an empty widget, because an empty widget invites a support ticket.
Field permissions
18 fields · 6 roles · changes take effect at the next nightly run and are written to the audit log
allow deny
Data field
{{ r.name }}
{{ r.accounts }}
{{ row.name }} {{ row.note }} Restricted domain
{{ row.name }} {{ row.source }}
Scope narrows a role's rows before field permissions apply. An agent with allow on commission revenue still sees only their own — own scope cannot be widened from this screen.