← All projects

Meta

Business account task-based permissions

Simplifying a complex permissions system so businesses can more confidently give people access to the tools and assets they need across Meta's business products.

Situation

Too many businesses were giving people access to sensitive information and tasks that they didn’t need in our business ecosystem.

  • In business accounts, 76% of admins in high-value businesses had permission to access sensitive information that they didn’t need
  • 26% of all multi-user monthly active businesses had at least one person who hasn’t been active in the last 28 days
  • 50-80% of users don’t use the tasks granted to them

When someone has permission to take more actions than they need (aka “overpermissioning”), it puts the business at risk either through accidental or malicious actions. We saw both qualitative and quantitative associations between overpermissioning and the likelihood of business compromise.

A major reason why people were given too much access was the lack of granularity in permissions offered. For businesses giving access to others on our business tools, there were just 2 roles for Business Account Access: employee and admin.

This was problematic because:

  • The roles didn’t always map to real-world titles and expectations
  • It implies things about the level of access that aren’t true
  • It isn’t granular or safe enough

We also knew from research that users struggled to understand what the roles meant. The actions that came with the role were not intuitive.

‍

Tasks

Task

I needed to provide more granularity than what we currently offer with admin, employee, finance, and developer roles. Our hypothesis was that by enabling people to assign specific tasks without giving full control, we could prevent overpermissioning issues and make businesses more secure.

I also needed to reframe the roles into independent tasks, so that users could give permissions for specific tasks people need to do their job.

Tasks

  • Define Business Account level granular tasks
  • Do an analysis of tasks to determine the right level of granularity
  • Create task labels and task descriptions
  • Update content in help articles
  • Sales comms
  • Update content across Meta
  • In-product guidance

‍

Actions

Strategic phase:

  • Led the strategy work, including working with cross-disciplinary teams to conduct an audit and analysis to break the admin role into tasks and determine the right level of granularity
  • Got input and gained alignment from at least 10 partners, working with teams like product marketing, business protection, and business integrity and security
  • Led overall project management by creating a project brief, posting regular project updates, and reviewing work with key stakeholders to provide transparency and solicit feedback
  • Influenced team to use partial access and full control structure to align with permissions framework. Defined granular tasks.

Execution phase:

  • Created in-product content, including task labels, task descriptions, and tooltips
  • Collaborated with the business education team to get help articles updated to explain the term changes
  • Worked with the internationalization team to do localization testing on new terminology

‍

Results

  • Built the foundation for task-based permissions that will enable the team to add more granular tasks so that people have the right amount of access to business accounts.
  • In user research, all participants said they would be able to assign appropriate permissions for the user in their business and understood the access categories.
  • Ship goal: Launched the terminology changes to 100%.
  • My work with the internationalization team on localization testing in 16 locales on new terminology resulted in 77 language improvements.
  • Our go-to-market strategy is to roll all the granular tasks out at once so that businesses can make their permission changes at one time. The plan is to roll out the changes in H2 2023. At that time, we will measure:
    • Reduction in the number of users who are over-provisioned to take high-risk actions or see sensitive information
    • Reduction in the number of users with permission to take actions they don’t use
    • Reduction in the number of security incidents

This project is a long-term effort. I built the foundation for a significant change in how people manage access to their business. This is the first step to addressing security and productivity issues by transitioning from roles to a task-based permissions structure.

‍