Role-Based Access Control (RBAC)

Role-Based Access Control is a security method that restricts network or system access based on a user's predefined job responsibilities. Instead of assigning permissions to individuals, the organisation groups privileges into roles, and users inherit the exact access required to perform their daily duties. This minimises operational risk and ensures strict adherence to data security principles.


The Three Base Roles

Every account on the DAC Enterprise Portal is categorised under one of three structural base roles, which define your authorisation tier within the system. These roles comprise Root, Super Admin, and User, with their respective responsibilities and privileges outlined below:

👑 1. Root

The highest authority on the platform. To maintain strict accountability, there is only one designated Root user per enterprise ecosystem.

  • Full Visibility: Holds comprehensive read/write access across all platform modules.

  • Gatekeeper Approvals: Reviews and authorises critical or sensitive actions initiated by Super Admins.

  • Compliance Management: Can assign or strip specialized Compliance Feature Roles for any user.

  • Separation of Duties: Cannot hold a Compliance Feature Role directly, ensuring a system of checks and balances.

📌 Summary: Think of the Root role as the final sign-off authority. They do not handle day-to-day data entry, but no high-risk system modifications can occur without their explicit approval.


🔧 2. Super Admin

Handles the core, day-to-day operations of the platform.

  • User Onboarding: Can invite new Users to the platform.

  • Rank-Based Management: Can manage, edit, and audit user profiles ranked below them.

  • Dual-Role Capacity: Eligible to hold an additional Compliance Feature Role (e.g., Compliance Director).

  • Approval Gates: Certain high-level actions require Root Admin approval before taking effect.

📌 Summary: Super Admins are the primary operators of the system. Most internal administrative staff will operate at this tier.


👤 3. User

A standard account layer with restricted, task-specific platform access.

  • Segmented Visibility: Access is strictly confined to modules relevant to their assigned role.

  • Management Restrictions: Locked out of the User Management panel by default.

  • Access Expansion: Can be granted a supplementary Compliance Feature Role to securely unlock additional feature sets.

📌 Summary: Most compliance team members who do not require system administration tools operate at this level, with specific operational permissions added on top via specialized features.


Quick Comparison

Root

Super Admin

User

Invite users

✅ Super Admin & User

✅ User only

Manage users

✅ (below their rank)

Hold a Compliance Role

Approve sensitive actions


Not Sure What Role You Have?

Log in to the DAC Admin Portal and go to your Profile page. Your role is displayed there. If you think your role is incorrect, contact your manager or the system administrator.


Was this article helpful?