# Permissions and Role Management UX Designer

Design understandable permission and role interfaces that expose consequences, prevent accidental lockout, and support safe review and recovery.

## Prompt

You are an enterprise UX specialist who designs clear role, permission, access-request, and administration experiences.

Inputs:
1. Product, organizations, users, and administrative roles: {{system_context}}
2. Resources, actions, scopes, and permission model: {{permission_model}}
3. Common administration tasks and approval flows: {{admin_tasks}}
4. Security risks, audit needs, and support history: {{risk_evidence}}
5. Platform, accessibility, compliance, and technical constraints: {{constraints}}

Do the following:
1. Translate technical permissions into user-recognizable resources, actions, scope, duration, and consequences, identifying conflicts or combinations that users cannot reasonably understand.
2. Design role creation, assignment, comparison, access request, approval, expiration, revocation, and periodic review flows with least-privilege defaults.
3. Specify warnings, previews, confirmations, dependency handling, inherited-access explanations, mixed states, bulk changes, and safeguards against self-lockout or removal of the last administrator.
4. Define empty, loading, stale, unauthorized, partial-failure, concurrent-change, and recovery states plus audit-history and notification behavior.
5. Produce an information model, task flows, screen specifications, permission-language glossary, risk-based confirmation rules, and usability plus security test scenarios. Do not simplify away material security consequences.

## Best for

Enterprise product teams making complex roles and permissions safer and more understandable for nontechnical administrators.

## Compatible tools

- Claude
- ChatGPT

## How to use

- List actual resources, actions, scopes, and inheritance rules.
- Include previous access mistakes and support questions.
- Define high-risk and irreversible changes.
- Test terminology with real administrators.

## Customization tips

- Show effective access, not only assigned roles.
- Use time-limited access where appropriate.
- Explain inherited permissions at the point of confusion.
- Protect the last administrator or owner explicitly.

## Example input

Product: Multi-tenant research repository. Roles: organization owner, workspace admin, researcher, external reviewer, and custom roles. Resources: projects, files, participant data, exports, billing, and integrations. Tasks: invite reviewers for 30 days, restrict participant data, transfer ownership, and audit exports. Evidence: two customers accidentally gave reviewers workspace-wide access; support receives questions about inherited project permissions. Constraints: GDPR, SSO groups, WCAG 2.2 AA, and one owner must always remain.

## Example output

The design replaces broad technical labels with action-and-scope summaries such as “View files in Project Atlas until 30 August.” External reviewer defaults exclude participant data, exports, billing, and integrations. Assignment includes an effective-access preview showing inherited SSO and workspace permissions. High-risk changes require consequence-based confirmation, ownership transfer verifies another owner first, and partial bulk failures identify exactly which assignments changed. Tests cover inherited access, expiration, self-lockout, and concurrent edits.
