Custodia Registry · A01
Users and roles
40 minutes. · 10 slides
Lesson video coming soon. The player below contains a sample video, not this lesson. You can use the written lesson and slide guide now.
Work through the lesson
Use these explanations alongside the slide guide. Expand any section to read its full explanation.
Your task and authority
- Confirm your assigned duties
- Use the fictional training case
- Verify the result and its history
Learning outcome
Administrator resolves missing access without granting blanket permissions.
Read the full explanation
Our audience is admin; custom account administrator; Soft admin subset. Before the demonstration, confirm these prerequisites: C01, C02; fictional training record and approved account. The action-level access conditions are: users.view/create/edit/delete; roles.manage; permissions.view. Check the actual account and record state. The goal is not simply to find a button: Administrator resolves missing access without granting blanket permissions.
Account and duties
- Inspect the approved training account and assigned roles.
What to check
Inspect the training account and its assigned roles. Compare the requested task with actual duties. A role name is a starting point; effective grants and record conditions determine the available action.
Read the full explanation
Inspect the approved training account and assigned roles. Inspect the training account and its assigned roles. Compare the requested task with actual duties. A role name is a starting point; effective grants and record conditions determine the available action. As we work through this example, identify the record or account involved and point out the evidence that confirms this step. If the expected control or result is missing, pause and explain the condition before continuing.
Presets and saving
- Compare a preset against the required duties before saving.
What to check
Review a preset before saving the role configuration. Selecting a preset populates choices; saving is a separate action. Soft admin has user-view authority by default, not user creation, editing or deletion.
Read the full explanation
Compare a preset against the required duties before saving. Review a preset before saving the role configuration. Selecting a preset populates choices; saving is a separate action. Soft admin has user-view authority by default, not user creation, editing or deletion. As we work through this example, identify the record or account involved and point out the evidence that confirms this step. If the expected control or result is missing, pause and explain the condition before continuing.
Explain a permission
- Use the record Permission explanation panel to diagnose one allowed and one blocked action.
What to check
Use the record’s Permission explanation panel for an allowed and blocked action. Check grants, clearance and state before proposing a change. Blanket authority hides the cause of the problem.
Read the full explanation
Use the record Permission explanation panel to diagnose one allowed and one blocked action. Use the record’s Permission explanation panel for an allowed and blocked action. Check grants, clearance and state before proposing a change. Blanket authority hides the cause of the problem. As we work through this example, identify the record or account involved and point out the evidence that confirms this step. If the expected control or result is missing, pause and explain the condition before continuing.
Sessions and activation
- Review account sessions and deactivate only the approved fictional account.
What to check
Review sessions and deactivate only the designated fictional account. Account active status is distinct from its role assignments. Custodia roles themselves do not have an inactive flag.
Read the full explanation
Review account sessions and deactivate only the approved fictional account. Review sessions and deactivate only the designated fictional account. Account active status is distinct from its role assignments. Custodia roles themselves do not have an inactive flag. As we work through this example, identify the record or account involved and point out the evidence that confirms this step. If the expected control or result is missing, pause and explain the condition before continuing.
Deletion dependencies
- Check dependencies before proposing account deletion and document the access change.
What to check
Inspect dependencies before proposing deletion. Preserve the history and accountability attached to an account. Use a tabletop example for deletion rather than removing a live user to demonstrate the control.
Read the full explanation
Check dependencies before proposing account deletion and document the access change. Inspect dependencies before proposing deletion. Preserve the history and accountability attached to an account. Use a tabletop example for deletion rather than removing a live user to demonstrate the control. As we work through this example, identify the record or account involved and point out the evidence that confirms this step. If the expected control or result is missing, pause and explain the condition before continuing.
Exceptions and recovery
- Identify the blocked condition
- Preserve the relevant evidence
- Use the authorized next step
Important boundary
Roles have no inactive flag; active account status and current grants are distinct. Soft admin includes users.view but not users.create/edit/delete by default. Do not use live account deletion as an exercise.
Read the full explanation
Consider the exception before deciding to retry. Roles have no inactive flag; active account status and current grants are distinct. Soft admin includes users.view but not users.create/edit/delete by default. Do not use live account deletion as an exercise. Explain what you expected and what was actually shown. Keep the record identifier and sanitized error context, then refer the issue to the person responsible for that decision. A missing or blocked control is not a reason to borrow a more powerful account.
Guided practice
- Work within the assigned role
- Show the resulting state
- Explain one exception
Your exercise
Diagnose one allowed and one blocked action for a fictional account. Explain the smallest appropriate access change and the limits of Soft admin.
Read the full explanation
Now use the approved fictional example. Diagnose one allowed and one blocked action for a fictional account. Explain the smallest appropriate access change and the limits of Soft admin. Explain the identity, current state and intended action before acting. At the end, show the evidence of the result and name the next responsible person if the workflow cannot proceed. Destructive actions and live external sends are discussed using prepared examples.
Practice debrief
- Correct identity and authority
- Traceable result and history
- A justified next step
Expected answer
The learner uses effective grants and record conditions, distinguishes presets from saving, and does not invent role deactivation or use live account deletion.
Read the full explanation
The answer should establish the following: The learner uses effective grants and record conditions, distinguishes presets from saving, and does not invent role deactivation or use live account deletion. Walk through the evidence in the same order as the workflow. Explain the specific boundary discussed in this lesson. If a result could not be established, report it as unverified and identify what would be needed to complete the task.