Distinguish sign-in, organization membership and task-specific permissions when setting up and using service access.
Who is this for? Customers and contact persons who need access to shared services or want to clarify existing access.
Use cases and context
A successful login first confirms the identity in the login service used. Whether a certain resource is visible also depends on the organization, role, and, if applicable, other access rules. Therefore, a login can succeed while a single area remains locked.
Authorizations should match the actual task. A contact person for quotations does not automatically need access to all commercial or technical data. Especially in the case of several organizations, the assignment must be unambiguous.
The approach in detail
- Describe the required task. Name the organization, desired service and technical contact person.
- Use the designated login path and complete required approvals. The role is assigned based on the confirmed responsibility.
- Check access to the required areas. If there are problems, send the time, affected page and a cleaned error message to the intended contact.
Expected outcomes
- Clear connection between person and organization
- Task-related instead of blanket access rights
- Comprehensible process for clarifying missing rights
- Plannable withdrawal of additions when changing roles
Prepare for an informed decision
Use the work email address provided for your organization. Don't send passwords, verification codes, or session tokens to support.
If multiple accounts are logged in to the browser, check the one you actually selected. Existing security rules are taken into account when solving the problem and are not circumvented by uncontrolled alternative access.
Questions and answers
Why can't I see everything despite logging in?
Login and permission are different steps. The desired role or organization assignment may be missing, or additional access conditions may apply.
What happens in the event of a change of responsibility?
Accesses and roles should be checked and adjusted. Rights that are no longer needed are withdrawn via the designated administrative process.