T
Telblu

Access & identity

Roles & Permissions

Telblu uses enterprise Role-Based Access Control (RBAC) to secure every surface of the platform. Permissions are never granted to individual users directly - they are bundled into roles, and roles are assigned within a defined organisational scope. The result is predictable, auditable access that scales with your operating model.

Permission model

Every action in Telblu maps to an atomic permission. Roles are curated bundles of these permissions - never granted directly to individual users.

Inheritance

Access granted at a higher scope flows down to every child scope. A CFO scoped to the organisation inherits visibility into every department.

Scope

A role assignment is always bound to a scope: Organisation, Department or Workspace. Scope determines what data the role can act on.

Default roles

Telblu ships with a curated set of default roles - Executive, Functional Leader, Department Leader, Manager, Contributor and Administrator - mapped to real operating responsibilities.

Role-Based Access Control

Telblu's authorisation model is built on two independent axes: what a user is allowed to do (their role) and where they are allowed to do it (their organisational scope). Every access decision - page load, API call, server function - is evaluated against both.

Role + Organisational Scope

A user's effective permissions are the intersection of the role they hold and the scope that role is bound to. The same role (e.g. Department Leader) can be assigned multiple times to the same user across different departments; each assignment is evaluated independently.

RoleScopeEffective access
ExecutiveOrganisationAll departments and workspaces
Department LeaderDepartmentAll workspaces within the department
ContributorWorkspaceOnly the assigned workspace

Inheritance chain

Permissions cascade downward through the organisational hierarchy. A role granted at a parent scope is automatically effective at every child scope beneath it - you never need to re-grant access at each level.

Organisation

The top of the hierarchy. Roles here see every department and workspace in the tenant.

Department

A functional group (Finance, Product, Sales). Access is limited to the teams and workspaces inside it.

Workspace

The leaf-level container for a team's strategy, priorities, metrics and reviews. Narrowest scope.

Organisation → Department → Workspace. Access granted above flows down; access granted below does not flow up.

Least-privilege access

Telblu enforces least-privilege by default. New users are created with no roles and no scope - they cannot see or act on any data until an administrator makes an explicit assignment. Roles bundle only the permissions required to perform a specific job function, and scope narrows those permissions to the smallest slice of the organisation the user needs.

  • Deny by default. Any request without a matching role + scope is rejected at the database layer via row-level security.
  • Explicit grants. Access is only granted through named role assignments - never through ad-hoc sharing or per-record ACLs.
  • Auditable. Every assignment, change and revocation is written to the audit log with actor, timestamp and previous state.

Permission inheritance diagram

The diagram below shows how a role granted at a higher scope cascades down to every child scope. Arrows represent the direction access flows.

OrganisationTenant rootFinanceDepartmentProductDepartmentSalesDepartmentFP&AWorkspaceTreasuryWorkspacePlatformWorkspaceGrowthWorkspaceEnterpriseWorkspace
OrganisationDepartmentWorkspace

Default platform roles

Telblu ships with five default roles that map to the most common operating responsibilities in an enterprise. Each role bundles a curated set of permissions and is always assigned within a specific organisational scope.

Platform Administrator

Scope: Organisation

Highest privilege

Purpose

Owns tenant-wide configuration: identity providers, authentication policies, role assignments, department structure, integrations and audit.

Typical users

IT admins, security engineers, internal operations, delivery lead during onboarding.

Can access

  • All organisations, departments and workspaces in the tenant
  • Audit log, security events and sign-in history
  • Identity provider, SSO and MFA configuration
  • Billing, entitlements and platform settings

Can edit

  • User accounts, role assignments and scope bindings
  • Organisation, department and team structure
  • Authentication and session policies
  • Integrations, API keys and webhooks

Cannot do

  • Author strategy, priorities or reviews on behalf of a department without an explicit role
  • Bypass audit - every administrative change is recorded
  • Access customer data outside their tenant

Executive

Scope: Organisation

Read-across, decision rights

Purpose

Provides whole-organisation visibility and decision rights over strategy, priorities, performance and risk. The role held by CEOs, functional C-suite and board contributors.

Typical users

CEO, COO, CFO, CRO, CMO, CTO, VP-level leaders, board members, PE partners.

Can access

  • every department and workspace across the organisation
  • Executive Control Centre and board-pack content
  • Draft and approved strategy, priorities and outlooks
  • Cross-functional risk, performance and governance intelligence

Can edit

  • Approvals and executive commentary on submitted strategy and priorities
  • Executive-level review sign-offs
  • Board-pack framing and narrative

Cannot do

  • Change tenant-level identity, SSO or role configuration
  • Modify department-owned content directly without acting as that department
  • Grant or revoke user access - that is the Administrator's responsibility

Department Leader

Scope: Department

Owns their department

Purpose

Owns the strategy, priorities, metrics and outlook of a single department. Responsible for what is submitted upward for executive approval.

Typical users

Heads of Finance, Product, Engineering, Sales, Marketing, People and other functional departments.

Can access

  • All workspaces inside their department
  • Their department's approved and draft content
  • Team-level performance and review history
  • Executive commentary directed at their department

Can edit

  • Departmental strategy, priorities and outlook
  • Metric targets, confidence calls and narrative
  • Submissions for executive approval
  • Team and workspace structure within their department

Cannot do

  • See other departments' draft or board-pack content
  • Approve their own submissions - approvals sit with executives
  • Assign platform-wide roles or change identity settings

Contributor

Scope: Workspace

Day-to-day operator

Purpose

Performs the day-to-day work inside a specific workspace - capturing metric updates, drafting content and raising blockers to the department leader.

Typical users

Team managers, individual contributors, analysts and operators assigned to a specific workspace.

Can access

  • Only workspaces they are explicitly assigned to
  • Approved strategy and priorities for their workspace
  • Their own metric history and review notes

Can edit

  • Metric updates, notes and evidence attachments in their workspace
  • Draft content pending department-leader review
  • Their own commitments and status updates

Cannot do

  • See draft or approved content from other workspaces
  • Submit content for executive approval
  • Change workspace, team or department structure

Viewer

Scope: Any (assigned)

Read-only

Purpose

Provides read-only visibility into approved content at the scope where the role is granted. Used for stakeholders who need transparency without decision rights.

Typical users

Non-executive directors, external auditors, advisors, cross-functional observers, new joiners in ramp-up.

Can access

  • Approved strategy, priorities, metrics and outlook at their assigned scope
  • Historical review outcomes and published narrative

Can edit

  • Nothing - the Viewer role is strictly read-only

Cannot do

  • Draft, edit or delete any content
  • Submit for approval or leave executive commentary
  • See draft or in-progress content that has not been approved
  • Change any configuration

Permissions matrix

A quick reference for what each default role can do. A green tick means the role holds the permission across its scope; a blue dot means the permission is granted, but limited to the scope the role is bound to (department, workspace, etc.).

PermissionAdminExecutiveDept. LeaderContributorViewer

View organisation

See the organisation tree and top-level metadata.

View departments

Browse departments and their published content.

Edit strategy

Draft and modify strategy content in a department.

Upload strategy

Attach and version strategy documents and evidence.

Review AI

Access AI review assistant output and act on recommendations.

Publish strategy

Move draft strategy to approved and visible upstream.

User management

Create users, assign roles and set scope bindings.

Authentication

Configure SSO, MFA, password and session policies.

Governance

Approve strategy, sign off reviews, enforce cadence.

Administration

Manage organisation, department structure.

Audit logs

Read the append-only audit trail for the organisation.

Reports

Generate and export reports across scopes.

Executive dashboards

Access the Executive Control Centre and board packs.

Full - permission held across the role's scopeScoped - limited to the assigned scopeNot granted

Permission evaluation

Telblu evaluates permissions dynamically on every request. There is no cached authorisation state - each API call, page load and server function re-runs the full check against the user's live role assignments and scope bindings.

1

User Login

Credentials submitted via SSO, password or MFA.

2

Authentication

Identity verified; session token issued.

3

Assigned Role

All role assignments for the user are loaded.

4

Scope Evaluation

Each role is resolved against its bound scope.

5

Permission Checks

Requested action mapped to atomic permissions.

6

Workspace Access

Row-level security filters records by scope.

7

Feature Access

UI surfaces and server functions are unlocked.

Stateless

Nothing is trusted from the client. The session token proves identity only - role and scope are re-read from the database on every request.

Dynamic

Revoking a role, changing scope or disabling a user takes effect on the next request - no cache purge, no re-login required.

Defence in depth

Checks run at three layers: the API gateway, the server function handler and the database row-level security policy. A misconfiguration at any single layer still fails closed.

Organisational scope

Every role assignment is bound to a scope. Scope determines the slice of the organisation the role can act on. Telblu supports four scope levels, each nested inside the one above.

Organisation

The tenant root. Assignments here see every department and workspace.

Enterprise example

A global manufacturer grants Executive scope at Organisation level to the CEO, CFO and COO so they see the full portfolio across every region.

Department

A functional group (Finance, Product, Sales, People). Assignments see every workspace inside that department only.

Enterprise example

A SaaS company scopes the VP of Product to the Product department; they own strategy across every product team but cannot read Sales' pipeline commentary.

Workspace

The leaf-level container for a team's strategy, priorities, metrics and reviews. The narrowest scope.

Enterprise example

A retail chain scopes a regional store manager to the workspace for their store - they update metrics locally, without visibility into other stores.

Delegated administration

Platform Administrators do not need to manage every user in every department. Telblu supports delegated administration: an admin can grant a Department Leader the ability to manage users, roles and structure inside their own department - without exposing tenant-wide identity or authentication settings.

Platform Administrator retains

  • Identity provider, SSO and MFA configuration
  • Tenant-wide role catalogue and permission definitions
  • department creation
  • Cross-organisation audit and compliance reporting

Department Leader (delegated) gains

  • Invite users into their department
  • Assign Contributor and Viewer roles at workspace scope
  • Create, rename and archive teams and workspaces
  • Read the audit log filtered to their department

Guardrails

Delegated administrators cannot elevate their own role, assign Executive or Administrator roles, or grant access outside their department. Every delegated action is written to the organisation-wide audit log.

Temporary access

Enterprises frequently need to grant time-boxed access - external auditors during a quarter-end review, board members reading the board pack, consultants delivering an implementation, or a colleague covering an absence. Telblu supports temporary permission elevation with mandatory expiry, so short-term access never becomes permanent by accident.

Use caseTypical roleScopeDuration
External auditViewerFinance department2–6 weeks
Board meetingViewer + Board PackOrganisation48 hours around the meeting
Consultant engagementContributorNamed workspace(s)Length of the statement of work
Implementation projectDepartment Leader (delegated)Target departmentProject go-live + 30 days
Leave coverSame as covered roleSame as covered roleAbsence window
  • Mandatory expiry. Every temporary assignment requires a start and end timestamp - indefinite temporary access is not permitted.
  • Automatic revocation. At expiry the role assignment is removed by the platform, not by a human. No manual clean-up is required.
  • Expiry notifications. The grantor is notified 72 hours before expiry so extensions or a permanent grant can be considered in advance.
  • Full audit. Grant, use and revocation events are all recorded with actor, reason and expiry timestamp.

Audit trail

Every permission change in Telblu is written to an append-only audit log. Records cannot be edited or deleted - they can only be read. The audit log captures the actor, target user, event type, previous and next state, timestamp and source IP.

Recent activity

Live view - sample events from the audit log

Append-only
EventTargetActorScopeTimestamp
User addedpriya.raman@northwind.comalex.miles (Admin)OrganisationToday, 09:42
Role changedjames.oduya@northwind.comalex.miles (Admin)Finance dept.Today, 08:15
Access revokedexternal.consultant@bcg.comAuto - expiry reachedProduct dept.Yesterday, 18:00
Temporary access grantedaudit.team@pwc.compriya.raman (Admin)Finance dept. · 28 daysYesterday, 14:22
Strategy ownership transferredGrowth workspacesam.oduya (Exec)Sales dept.Mon, 11:05

Audit records are retained in full for the life of the tenant and are exportable in CSV or JSON for downstream SIEM, compliance and internal-audit tooling.

Security best practices

The following guidance is drawn from customer implementations and enterprise security reviews. Apply it during initial rollout and revisit each recommendation at every quarterly access review.

Least privilege

Best practice
Grant the narrowest role and scope that lets a user complete their job. Prefer Contributor at Workspace scope over Department Leader at Department scope when the user only needs to update metrics in a single team. Broaden access later on request, not up front.

Quarterly permission reviews

Info
Schedule a recurring access review every calendar quarter. Ask each Department Leader to confirm the current role and scope assignments for their team, and revoke any assignment that cannot be justified.

SAML SSO configuration

Best practice
Administrators configure SAML 2.0 identity providers and email domains per organisation from Administration → SSO. End users on configured domains are automatically routed to their identity provider on sign-in, and roles remain administrator-assigned per organisation.

Multi-factor authentication

Warning
Enrol every Administrator and Executive in TOTP multi-factor authentication using a standard authenticator app, and store the recovery codes securely. SMS, WebAuthn, passkeys and hardware keys are not implemented in this release.

Department ownership

Best practice
Every department should have at least two named Department Leaders. A single owner creates a governance gap during absence and blocks quarterly reviews when the owner leaves. Pair the primary owner with a deputy at creation time.

Removing inactive users

Warning
Users who have not signed in for 60 days should be reviewed; users inactive for 90 days should be disabled. Automate this with the inactive-user report and a scheduled revocation job. Never leave leavers with active role assignments after their last working day.

Enterprise example

The diagram below models a mid-market technology company - Northwind Analytics, ~850 employees - showing how role and scope assignments flow from the CEO down to individual contributors and read-only viewers.

Sarah Chen - Chief Executive

Role: Executive · Scope: Organisation

Sees every department and workspace. Approves company-level strategy and board pack.

David Okafor - CFO

Role: Executive · Scope: Organisation

Approves financial strategy across every department, owns the board pack finance section.

Priya Raman - COO

Role: Executive · Scope: Organisation

Owns cross-functional operational risk, reviews weekly performance across all departments.

James Whitfield - Managing Director, EMEA

Role: Executive · Scope: Organisation (EMEA departments)

Sees only the departments within the EMEA remit.

Anna Novak - Head of Finance (FP&A)

Role: Department Leader · Scope: FP&A

Owns FP&A department strategy, priorities and metrics. Submits for CFO approval.

Marcus Lee - VP Product

Role: Department Leader · Scope: Product

Owns Product department; delegated admin for adding contributors to product teams.

Ines Duarte - Head of Enterprise Sales

Role: Department Leader · Scope: Enterprise Sales

Owns Enterprise Sales in the EMEA remit under James Whitfield.

Thomas Reid - FP&A Analyst

Role: Contributor · Scope: Treasury workspace

Updates monthly forecast metrics and treasury workspace notes.

Aisha Bello - Product Manager, Platform

Role: Contributor · Scope: Platform workspace

Drafts product priorities pending Marcus Lee's review.

PwC Audit Team

Role: Viewer (Temporary) · Scope: FP&A · Expires 30 Nov

Time-boxed access for Q3 external audit; automatic revocation on 30 Nov.

Board Observer - Meridian Capital

Role: Viewer · Scope: Organisation (approved content)

Read-only visibility into approved board pack content only.