Roles and permissions
Check explicit permissions, not role names.
Step by step
- Read the role, its status and operation permissions.
- Match permissions to the person’s work. Reading, creating and confirming may require different rights.
- Read the role’s current permissions and status before changing it. Role updates have no version field. Assign or remove the exact role explicitly for the intended member or API client; a list of current assignees is not exposed by this API.
- A new role grants nothing until explicitly assigned. New system capabilities are not automatically added to existing roles.