Role-based access means granting access by job role rather than person by person. A scaler, a buyer, a controller and a yard manager each get a role, and the role carries the permissions. When someone joins, moves or leaves, their role changes and their access follows. A national standards body's project page notes that role-based access control "has become the predominant model for advanced access control". Without roles, administrators "specify access control lists for each user on the system individually", which is slow and "prone to error". The same page reports that, as of 2010, "the majority of users in enterprises of 500 or more were using RBAC", according to an analysis by the research institute RTI International.
Where it goes wrong
Roles drift. Permissions are added for a one-off task and never removed. People move jobs and keep their old role as well as the new one. Roles can multiply until there is nearly one per person.
Roles also have a limit. A role can say "contractors may read tickets". It can't say "each contractor may read only their own tickets". That needs row-level rules on top of the role.
AI tools and roles
Businesses now connect AI assistants and agents to their systems. It is easy to give them the role of whoever set them up, which may be an administrator. Then anyone who can use the tool sees what the administrator sees.
For an assistant that answers users' questions, the safer pattern is usually to act with the asking user's own access. Microsoft's Copilot Studio documentation offers exactly that choice: "User authentication" for data "that only the user has access to". A narrow role of the tool's own suits unattended agents and integrations, read-only by default.
In a timber business
Sensitive data includes stumpage and log prices, customer pricing, margins and contractor pay rates. A sales role may need customer prices but not log costs.
What to check
List the roles and what each can see and change. Review membership when people change jobs, and review the roles on a schedule. Ask whether each AI tool acts with the user's access or its own.
What it isn't
Role-based access isn't least privilege by itself, since a role can still be too broad. The two work together.
Quarri's security page sets out how customer data is isolated, encrypted and audited.
Sources
- NIST Computer Security Resource Center, "Role Based Access Control" project, updated 4 March 2026: csrc.nist.gov
- Microsoft Learn, "Configure user authentication for tools", Copilot Studio, last updated 7 April 2026: learn.microsoft.com
Quarri is an AI-native data platform for the timber supply chain. It connects buying, production, sales and inventory for forest management, sawmill, wood products and pulp, paper and packaging operators.