====== Role ====== [[dido:99_annexes:annex-b-terms-and-definitions:start|Go up to Terms and Definitions]] ===== Discussion ===== A Role is a named set of responsibilities, permissions, and expected behaviors assignable to an [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actor]] within a defined context. An Actor can include: * A person * A [[dido:99_annexes:annex-b-terms-and-definitions:u:user|User]] * An [[dido:99_annexes:annex-b-terms-and-definitions:o:organization|Organization]] * An organizational unit * A system * A service * A [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Node]] * Another participant capable of performing assigned responsibilities A Role can establish: * Responsibilities * Permitted actions * Prohibited actions * Required actions * Decision rights * Access permissions * Approval authority * Accountability * Separation-of-duty constraints * Qualification requirements * Applicable [[dido:99_annexes:annex-b-terms-and-definitions:p:policy|Policies]] * Applicable [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_policy|Governance Policies]] A Role can identify: * Its identity * Its name * Its description * Its responsibilities * Its permissions * Its constraints * Its applicable context * Its applicable [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_domain|Governance Domains]] * Its assigning authority * Its eligible Actor types * Its qualification requirements * Its incompatible Roles * Its delegation rules * Its effective time * Its expiration time * Its [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] * Its [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] ===== Definition ===== //named set of responsibilities, permissions, and expected behaviors assignable to an [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actor]] within a defined context// ===== Source ===== Adapted from: * DIDO Reference Architecture * DIDO Reference Implementation Conceptual Model * DIDO-TE draft Requirements Register ===== Note ===== A Role differs from an [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actor]]: * A Role specifies responsibilities, permissions, and expected behaviors * An Actor performs or assumes the Role A Role differs from a [[dido:99_annexes:annex-b-terms-and-definitions:u:user|User]]: * A Role identifies responsibilities, permissions, and expected behaviors * A User identifies a person, Organization, or system that interacts with or uses a system, service, or Resource A User can act in multiple Roles. Multiple Users can act in the same Role. A Role differs from an organizational position: * A Role specifies responsibilities and behavior within a context * An organizational position identifies a place within an organizational structure An organizational position can receive one or more Roles. Assigning a Role to an Actor does not necessarily grant every permission associated with the Role. The assignment must satisfy the applicable authorization, qualification, scope, time, and Governance Policy constraints. A Role can apply at multiple architectural levels. For example: * A person can perform a Test Operator Role * A Node can perform a Validation Role * An Organization can perform a Governing Authority Role * A service can perform an Evidence Collection Role A Role does not determine its implementation. Different Actors can realize the same Role through different technologies, processes, or organizational arrangements. A Role assignment should preserve: * The assigned Actor * The assigned Role * The assigning Authority * The applicable scope * The effective time * The expiration time * The applicable constraints * The applicable Provenance * The applicable Traceability ===== Example ===== DIDO-TE defines the following Roles: * Test Administrator * Test Designer * Test Operator * Evaluator * Evidence Custodian * Baseline Manager * Approval Authority A User acting in the Test Operator Role can initiate an approved [[dido:99_annexes:annex-b-terms-and-definitions:t:test_run|Test Run]]. A User acting in the Evaluator Role can review the resulting [[dido:99_annexes:annex-b-terms-and-definitions:t:test_result|Test Results]] and supporting [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]. A User acting in the Approval Authority Role can make the applicable [[dido:99_annexes:annex-b-terms-and-definitions:v:validation_decision|Validation Decision]]. The Roles remain distinct even when one User receives more than one Role, subject to the applicable separation-of-duty constraints. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.