Reference
AMS Role and Access Matrix
Use least privilege across operators, custodians, auditors, finance reviewers, and administrators.
First created Last updated
amsaccessrolessecurity
| Role | Typical access | Must not bypass |
|---|---|---|
| Borrower/custodian | Own assignments, due dates, acknowledgements, approved return actions. | Broad register, other people’s contact data, policy administration. |
| Asset operator | Registers, scans, approved custody/transit/audit operations. | Actor attribution, protected evidence, approval separation. |
| Audit/maintenance lead | Scoped counts, work, variance review. | Required independent approval. |
| Finance reviewer | Value and policy-controlled workflows. | Maker-checker and closed-period controls. |
| AMS administrator | Shared master data and capability configuration. | Immutable historical actor/event facts. |
Step-up and dual-control requirements depend on organization policy and the risk of the action.