Seven role families operate across layered boundaries: system, tenant, client, vendor, and
assignee portal. Each needs a fixed permission baseline, scope boundary, and audit behaviour.
Actor · Gallagher · Admin Tier
Platform Administrator
Gallagher's internal platform admin who manages tenant-level configuration: creates and modifies roles, assigns permission sets, manages SSO/IdP integration, configures MFA policies, and audits access logs. Has full system access but operates under change-management controls — all role changes are logged and require a second admin to approve in production.
Scope: All tenants · All settings · Dual-approval required
Permissions: Full access to all 11 platform capabilities including user/role management, audit logs, SSO config, and API access.
Actor · Gallagher · Operator Tier
Service Delivery Consultant
Gallagher's operational consultant who manages day-to-day assignment coordination for specific clients. Has read/write access to assignee records and workflow actions for their assigned client portfolio only. Cannot access platform admin settings, other consultants' client portfolios, or billing/contract data.
Scope: Assigned client portfolio only
Permissions: View/edit assignees (portfolio-scoped), read policies, read financial data, scoped API access. No approval, user management, audit log, or SSO access.
Actor · Client · Admin Tier
Client Organisation Admin
The client's designated admin (typically IT or senior HR) who manages their organisation's users within the platform. Can invite/remove users, assign roles within their tenant, configure approval workflows, and view audit logs for their organisation. Cannot access other client tenants or modify platform-level settings.
Scope: Own tenant only · User management · Approval config · Audit logs
Permissions: Full assignee access (tenant), tenant-scoped export, full policy config, tenant user/role management, tenant audit logs, read-only SSO, full financial data, tenant API access.
Actor · Client · Operator Tier
HR Manager / Mobility Lead
Client-side HR professional who manages assignee records, initiates and approves assignments, runs reports, and configures policy parameters within their granted scope. Sees all assignees in their business unit or region. Cannot modify RBAC settings, SSO configuration, or access other business units unless explicitly granted cross-unit visibility.
Scope: Business unit or region
Permissions: View/edit/approve assignees (BU/region), opt-in export, read policies, BU-scoped financial data and documents, scoped API access. No user management, audit logs, or SSO access.
Actor · Client · Consumer Tier
Assignee (End User)
The relocating employee who accesses the self-service portal to view their assignment details, upload documents, track relocation milestones, and submit expense claims. Sees only their own data. Cannot view other assignees, access admin panels, or modify policies.
Scope: Own data only
Permissions: View own assignee record, edit own PII, export own data, upload own documents. No policy config, user management, audit logs, SSO, financial data, or API access.
Actor · Client · Consumer Tier
Finance / Payroll Viewer
Client finance team member with read-only access to cost estimates, compensation data, tax equalisation reports, and budget dashboards. Cannot view personal assignee documents (passport, medical), cannot modify records, and cannot approve assignments.
Scope: Cost centre hierarchy · Read-only financial data · No PII access
Permissions: Financial data export (read-only), read-only API access. No assignee viewing, editing, approvals, policy config, user management, audit logs, SSO, or document/PII access.
Actor · Vendor · Scoped Tier
Vendor / Provider Portal User
A third-party provider that may update only the screens or milestones they are assigned to: household goods, destination services, immigration, tax, housing, or other provider-owned work. Vendor users must not see the full assignee page unless explicitly required.
Scope: Assigned provider work only
Permissions: Update scoped milestones, upload provider documents, view assigned tasks, no tenant-wide data, no unrelated assignee records, no financial exports unless contracted.