Meta
Simplifying a complex permissions system so businesses can more confidently give people access to the tools and assets they need across Meta's business products.

Too many businesses were giving people access to sensitive information and tasks that they didn’t need in our business ecosystem.
When someone has permission to take more actions than they need (aka “overpermissioning”), it puts the business at risk either through accidental or malicious actions. We saw both qualitative and quantitative associations between overpermissioning and the likelihood of business compromise.
A major reason why people were given too much access was the lack of granularity in permissions offered. For businesses giving access to others on our business tools, there were just 2 roles for Business Account Access: employee and admin.
This was problematic because:
We also knew from research that users struggled to understand what the roles meant. The actions that came with the role were not intuitive.
Task
I needed to provide more granularity than what we currently offer with admin, employee, finance, and developer roles. Our hypothesis was that by enabling people to assign specific tasks without giving full control, we could prevent overpermissioning issues and make businesses more secure.
I also needed to reframe the roles into independent tasks, so that users could give permissions for specific tasks people need to do their job.
Tasks
Strategic phase:
Execution phase:
This project is a long-term effort. I built the foundation for a significant change in how people manage access to their business. This is the first step to addressing security and productivity issues by transitioning from roles to a task-based permissions structure.