Vendor Management Roles and Access
Access should follow the role, not the person
Permissions granted one request at a time are the reason most organisations cannot say why a particular person can see a particular thing. Roles are the fix, and they only work if they are the default rather than the exception.
Because permissions accumulate and roles do not
Individual grants feel flexible and become unmanageable. The problem is not the first grant, it is the two hundredth.
Access is reviewable in an hour
There are far fewer roles than people, so checking who can do what means examining a handful of roles rather than every individual in turn.
Job changes do not leave residue
Moving from buying to compliance moves the access rather than adding to it, which is how people end up able to approve their own work.
History survives departures
Removing somebody's access does not remove their entries. What they did stays attributed to them because the record describes what happened.
And why nobody can explain it later
Every organisation starts with sensible access and ends up with a configuration nobody owns.
Per person, on request
Somebody needs to see something, so they are given it. Three years later the permission set is a record of past requests rather than a design.
Per role, by design
A role carries its scope and people are placed in roles, so access is intentional rather than accumulated.
Permissions stack
The new access is added and the old is rarely removed, which quietly creates people who can act on both sides of a control.
Access moves
Changing role changes what somebody can do, rather than extending it.
A gap in the record
Removing a person sometimes takes their history with them, leaving a record that cannot say who did what.
History preserved
Access is removed while their entries remain attributed, because the record describes events rather than current staff.
A setup task
New starters wait for someone to configure their access, which takes as long as it takes.
An email invitation
Invited with a role and productive the same day, with permissions arriving from the role rather than being assembled.
Moments a procurement team will recognise
A new colleague starts Monday
Invited by email with a role, productive the same day, nothing to configure.
Learn moreSomebody moves from buying to compliance
Access follows the new role rather than layering on top of the old one.
Learn moreAn auditor asks who can approve
Answered by listing a handful of roles rather than every individual account.
Learn moreA colleague leaves
Access removed, their entries still attributed, no gap in the supplier history.
Learn more












