Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Roles installed with Public Sector Digital Services

The Public Sector Digital Services application uses roles to provide access to information, identify internal and external users, and establish different types of relationships between users. These roles control access to public sector data through UI-based features such as forms and lists.

Persona-based Roles in Public Sector Digital Services

Roles and personas help you to understand the different roles involved in Public Sector Digital Services.

Public Sector Digital Services supports users with the following basic job functions (personas). Personas are defined as the individual roles that perform different tasks in Public Sector Digital Services.

The following graphic shows the most common personas used throughout Public Sector Digital Services.

Image omitted: PSDS\_user\_personas.png
Common Public Sector Digital Services personas
Job functionDescription
ConstituentsEnd user, such as citizens, visitors, residents, soldiers, veterans, etc. Constituents can: - Request services from government agencies. - Track resolution of requests.
Government case agentsStaff member of an agency​, such as a constituent agent, business agent, agency agent, that delivers services to constituents or other agencies, and can​ requests services from other agencies. Agents can: - Works on government service cases for all constituents. Can read, write, and update all government service cases and profile records. - Can belong to specific teams or agencies. - Can work on specific case types \(for example Licenses or Unemployment\).
ContributorsBusiness stakeholder or requester for constituents: - Help constituents or businesses with services that they need. - Submits requests on behalf of constituents and acts as proxy.
AdminsSystem administrator, who has access to all system features, functions, and data, regardless of security restraints. Admins can: - Administers specific scoped apps built using different case types. - Manages the information for constituents.
Business stakeholderEnd user, such as business owner, business channel, or business partner. Business stakeholders can: - Request services from government agencies. - Track resolution of requests.
Business contactAn end user that is employed by a business. Business contacts can:- Request services from the government agencies - Register and create a login - Create and monitor cases - Track the resolution of requests and all services received
Government service agency managerManager or leader of an agency​ that provides constituent and business services. Manages agents supporting constituent services: - Administers services delivered to constituents, business stakeholders, and agency. - Can read, write, update, and delete all government service cases. - Can read, write, update, and delete all constituent, business, and agency records. - Manages staff of agency and can override agent actions​. - Tracks the resolution of requests and improves service delivery and constituent satisfaction.

Core Roles

Role title \[name\]DescriptionContains roles
constituent\[sn\_gsm.constituent\]Enables constituents to request services and manage their information, government service cases, and services received.- sn\_install\_base.sold\_product\_authorized\_consumer - sn\_gsm.service\_received\_read\_granular - sn\_customerservice.consumer - sn\_gsm.case\_write\_granular
constituent\_agent\[sn\_gsm.constituent\_agent\]Enables agents to perform the following actions:- Read, write, and update government service cases for all constituents. - Read, write, and update constituent records.- sn\_gsm.report\_viewer - sn\_gsm.case\_writer - sn\_gsm.service\_offered\_writer - sn\_customerservice.consumer\_agent - sn\_gsm.constituent\_writer - interaction\_agent
constituent\_contributor\[sn\_gsm.constituent\_contributor\]Enables users to request services and raise government service cases on behalf of any constituent.- sn\_customerservice.consumer\_contributor - sn\_gsm.contributor\_creator - sn\_customerservice.case\_authorized\_contributor
constituent\_admin\[sn\_gsm.constituent\_admin\]Provides agents with admin access and enables them to create, read, update, and delete constituent records.sn\_gsm.constituent\_writer
constituent\_writer\[sn\_gsm.constituent\_writer\]Provides agents with access to create, read, and update constituent records.sn\_gsm.constituent\_viewer
constituent\_viewer\[sn\_gsm.constituent\_viewer\]Provides agents with read-only access to constituent records.sn\_customerservice.customer\_data\_viewer
Role title \[name\]DescriptionContains roles
business\_contact\[sn\_gsm.business\_contact\]Enables business stakeholders to request services and manage information, government service cases, and services received.- sn\_customerservice.customer - sn\_install\_base.sold\_product\_authorized\_consumer - sn\_gsm.service\_received\_read\_granular - sn\_gsm.case\_write\_granular
business\_contact\_admin\[sn\_gsm.business\_contact\_admin\]Provides a business stakeholder with admin access to a business account. This role has access to all the data within the business account.- sn\_customerservice.customer\_admin - sn\_gsm.business\_contact
business\_case\_manager\[sn\_gsm.business\_case\_manager\]Enables a business stakeholder to manage government service cases for a business account and associated child accounts. This role can perform the following actions:- Create a case on behalf of another business contact. - View a list of cases belonging to the business. - Edit cases belonging to the business.- sn\_customerservice.customer\_case\_manager - sn\_gsm.business\_contact
business\_contributor\[sn\_gsm.business\_contributor\]Enables business stakeholders to request services and raise government service cases on behalf of any business.- sn\_customerservice.relationship\_contributor - sn\_gsm.contributor\_creator - sn\_customerservice.case\_authorized\_contributor
business\_partner\[sn\_gsm.business\_partner\]Enables business partners to create, view, and edit government service cases from their own account or from a business account that they are associated with.- sn\_customerservice.partner - sn\_gsm.business\_contact
business\_partner\_admin\[sn\_gsm.business\_partner\_admin\]Provides a business stakeholder with admin access to a partner account. This user can access all the data within the partner account and the government service cases created by the partners.- sn\_customerservice.partner\_admin - sn\_gsm.business\_partner - sn\_gsm.business\_contact - sn\_gsm.business\_contact\_admin
business\_agent\[sn\_gsm.business\_agent\]Enables agents to perform the following actions:- Read, write, and update government service cases for all business accounts. - Read, write, and update business records.- sn\_gsm.report\_viewer - sn\_gsm.case\_writer - sn\_gsm.service\_offered\_writer - sn\_customerservice.consumer\_agent - sn\_gsm.business\_writer - interaction\_agent
Role title \[name\]DescriptionContains roles
agency\_agent \[sn\_gsm.agency\_agent\]Enables agency agents to create and fulfill government service cases for the businesses and business contacts associated with the agency.sn\_customerservice.svc\_location\_agent
agency\_constituent\_agent \[sn\_gsm.agency\_constituent\_agent\]Enables agency agents to create and fulfill government service cases for constituents and households associated with the agency.sn\_customerservice.svc\_location\_consumer\_agent
agency\_contributor\[sn\_gsm.agency\_contributor\]Enables agency agents to request services and raise government service cases on behalf of the agency.- sn\_customerservice.service\_organization\_contributor - sn\_gsm.contributor\_creator - sn\_customerservice.case\_authorized\_contributor
agency\_manager\[sn\_gsm.agency\_manager\]Enables an agency manager to perform the following actions:- Create and update government service cases for constituents, households, business, and business contacts. - Manage data for constituents and households associated with the agencies within the agency hierarchy. - Manage data for businesses and business contacts associated with the agencies within the agency hierarchy.- sn\_customerservice.svc\_location\_manager - sn\_gsm.agency\_agent - sn\_gsm.agency\_constituent\_agent
agency\_manager\_contributor\[sn\_gsm.agency\_manager\_contributor\]Enables users to create, update, view, and approve cases. Allows them to register and remove staff across all agencies they manage. - "sn\_gsm.business\_contributor - sn\_gsm.government\_agency\_contributor - sn\_gsm.constituent\_contributor - sn\_gsm.government\_agency\_contributor - sn\_gsm.agency\_manager\_core - sn\_customerservice.svc\_location\_manager\_contributor"
relationship\_manager\[sn\_gsm.agency\_relationship\_manager\]Enables users to view cases across all the external agencies where they have location\_relationship\_manager responsibility.- sn\_bus\_loc.location\_relationship\_manager - sn\_gsm.agency\_manager\_contributor
service\_manager\[sn\_gsm.service\_manager\]Enables a service manager to perform the following actions:- Manage all work performed by agents working on government service cases. - Read, write, update, and delete all government service cases. - Read, write, update, and delete all constituent, business, and agency records.- sn\_gsm.service\_offered\_admin - sn\_gsm.service\_offered\_writer - sn\_gsm.constituent\_agent - sn\_gsm.constituent\_admin - sn\_gsm.business\_agent
Role title \[name\]DescriptionContains roles
admin\[sn\_gsm.admin\]Provides a user with delegated admin access to scoped applications created on the Public Sector Digital Services platform.sn\_gsm.service\_manager
service\_offered\_admin\[sn\_gsm.service\_offered\_admin\]Provides users with admin access and enables them to create, read, update, and delete services-offered records and services-received records.sn\_gsm.service\_offered\_writer
service\_offered\_admin\[sn\_gsm.service\_offered\_admin\] None
service\_offered\_writer\[sn\_gsm.service\_offered\_writer\]Provides users with access to create, read, and update services-offered records and services-received records.sn\_gsm.service\_offered\_viewer
service\_offered\_viewer\[sn\_gsm.service\_offered\_viewer\]Provides users with read-only access to services offered records and services-received records.sn\_customerservice.customer\_data\_viewer
case\_writer\[sn\_gsm.case\_writer\]Provides agents with access to create, read, and update government service cases.sn\_gsm.case\_viewer
case\_viewer\[sn\_gsm.case\_viewer\]Provides agents with read-only access to government service cases.None
contributor\_creator\[sn\_gsm.contributor\_creator\]Enables agents or business stakeholders to create government service cases and is included in the top-level contributor roles. This role can create cases but cannot view other cases.None
relationship\_agent\[sn\_gsm.relationship\_agent\]Enables agents to work on government service cases for customers that they have relationship with.- sn\_gsm.report\_viewer - sn\_customerservice.relationship\_agent
relationship\_contributor\[sn\_gsm.relationship\_contributor\]Enables business stakeholders to raise government service cases on behalf of customers that they have relationship with.- sn\_customerservice.relationship\_contributor - sn\_gsm.contributor\_creator - sn\_customerservice.case\_authorized\_contributor

Roles by Application

Note: Service Request Playbook does not contain roles that are separate from Public Sector Digital Services Core.

Role title \[name\]DescriptionContains roles
icm.investigator\[sn\_gsm\_icm.investigator\]Provides users the ability to create and work on the investigative cases. It includes read access to all the cases and write access to the cases which are assigned to the investigator.- sn\_gsm\_icm.case\_writer - sn\_gsm\_icm.case\_viewer - sn\_gsm\_icm.entity\_viewer - sn\_gsm\_icm.entity\_writer - sn\_gsm\_icm.report\_viewer - sn\_gsm.government\_service\_manager - sn\_gsm\_icm.investigative\_contributor
supervisory\_agent\[sn\_gsm\_icm.supervisory\_agent\]Provides users the ability to create and work on investigative cases. It includes read access to all the cases and write access to the cases belonging to the user's assignment group.- sn\_gsm\_icm.investigator - sn\_gsm\_icm.case\_admin
special\_agent\[sn\_gsm\_icm.special\_agent\]Provides users the ability to create and fulfill all cases.- sn\_gsm\_icm.investigator - sn\_gsm\_icm.case\_admin
expert\_analyst\[sn\_gsm\_icm.expert\_analyst\]Provides read or write access to the cases where these users are team members of the case or assigned to a case task of the case.- sn\_gsm\_icm.case\_viewer - sn\_gsm\_icm.case\_writer - sn\_gsm\_icm.event\_viewer - sn\_gsm\_icm.entity\_writer - sn\_gsm\_icm.event\_viewer
investigative\_contributor\[sn\_gsm\_icm.investigative\_contributor\]Provides read or write access to the cases where these users are team members of the case or assigned to a case task of the case.- sn\_gsm\_icm.case\_viewer - sn\_gsm\_icm.case\_writer - sn\_gsm\_icm.event\_viewer - sn\_gsm\_icm.entity\_viewer
case\_viewersn\_gsm\_icm.case\_viewerProvides users read only access to Investigative Case records.sn\_gsm.case\_viewer
entity\_viewersn\_gsm\_icm.entity\_viewerProvides read access to all the investigative case management entities such as Person, Organization, Property, Vehicle, or Evidence.None
event\_viewersn\_gsm\_icm.event\_viewerProvides read access to all the investigative case management events.None
report\_viewersn\_gsm\_icm.report\_viewerProvides users access to view reports containing Information Request data.sn\_gsm.report\_viewer
case\_admin\[sn\_gsm\_icm.case\_admin\]Provides read and write access to all the investigative cases.- sn\_gsm\_icm.case\_writer - sn\_gsm\_icm.case\_viewer - sn\_gsm\_icm.event\_writer - sn\_gsm\_icm.entity\_writer - sn\_gsm\_icm.report\_viewer
icm.admin\[sn\_gsm\_icm.admin\]Provides delegated admin access to the investigative case management application.- sn\_gsm\_icm.supervisory\_agent - sn\_gsm\_icm.special\_agent
case\_task\_agent\[sn\_gsm\_icm.case\_task\_agent\]Provides read access for administrative purposes to cases where users are assigned to a case task of the case.sn\_gsm.case\_task\_agent
case\_writersn\_gsm\_icm.case\_writerProvides users write only access to investigative case records that are assigned to the users or where the users are team members or where the case task of the case is assigned to the user.- sn\_gsm.case\_writer - sn\_gsm\_icm.case\_viewer
entity\_writersn\_gsm\_icm.entity\_writerProvides write access to all the investigative case management entities like Person, Organization, Property, Vehicle or Evidence.sn\_gsm\_icm.entity\_viewer
event\_writersn\_gsm\_icm.event\_writerProvides write access to all the events which the user has access to.sn\_gsm\_icm.event\_viewer
Role title [name]DescriptionContains roles
   
   
   
   
Role title \[name\]DescriptionContains roles
grant\_admin sn\_gsm\_grnt\_mgmt.grant\_adminProvides users with admin access and enables them to create, read, update, and edit grant proposals in the grant setup and proposals playbooks.- sn\_gsm.admin - sn\_svc\_appl\_pgm\_mg.grant\_program\_director
grant\_program\_director sn\_gsm\_grnt\_mgmt.grant\_directorProvides users with the grant program director role, which consists of the grant program manager and the government service manager roles.- sn\_gsm\_grnt\_mgmt.program\_manager - sn\_gsm.government\_service\_manager
external\_reviewer\[sn\_gsm\_grnt\_mgmt.external\_reviewer\]Enables merit review users to review and score grant proposals from within the Reviewer Service Portal.- sn\_svc\_appl\_pgm\_mg.resource\_role\_viewer - sn\_svc\_appl\_pgm\_mg.milestone\_viewer - sn\_svc\_appl\_pgm\_mg.resource\_mapping\_viewer - sn\_svc\_appl\_pgm\_mg.scoring\_framework\_attribute\_writer - sn\_svc\_appl\_pgm\_mg.business\_calendar\_entry\_viewer - sn\_svc\_appl\_pgm\_mg.resource\_assignment\_viewer - sn\_svc\_appl\_pgm\_mg.scoring\_framework\_viewer - sn\_svc\_appl\_pgm\_mg.planning\_item\_viewer
grant\_case\_writer sn\_gsm\_grnt\_mgmt.case\_writerProvides users with access to create, read, and update grant management case records.- sn\_gsm\_grnt\_mgmt.case\_viewer - sn\_gsm.case\_writer - contract\_manager
grant\_case\_viewer sn\_gsm\_grnt\_mgmt.case\_viewerProvides users with read-only access to grant management case records.- sn\_gsm.case\_viewer - decision\_table\_reader - sn\_gsm\_grnt\_mgmt.case\_writer
grant\_management\_report\_viewersn\_gsm\_grnt\_mgmt.report\_viewerEnables users to view reports about the grants management playbooks.None
Role title \[name\]DescriptionContains roles
License & Permits Install base writer\[sn\_gsm\_lic\_prmt.ib\_writer\]Provides create, read, and write access to Install base items.sn\_gsm\_lic\_prmt.ib\_writer
License & Permit Constituent Agent\[sn\_gsm\_lic\_prmt.constituent\_agent\]Enables users to work on License & Permit cases for all constituents. It includes the ability to read/write/update all License & Permit cases and constituent records- sn\_gsm.constituent\_agent - sn\_gsm\_lic\_prmt.case\_writer - sn\_gsm\_lic\_prmt.report\_viewer - sn\_gsm\_lic\_prmt.ib\_viewer - sn\_gsm\_lic\_prmt.manager
License & Permit Agency Manager\[sn\_gsm\_lic\_prmt.agency\_manager\]Enables users to manage data for agencies in the manager's agency hierarchy.- sn\_gsm.agency\_manager - sn\_gsm\_lic\_prmt.agency\_constituent\_agent - sn\_gsm\_lic\_prmt.agency\_agent
License & Permit Agency Constituent Agent\[sn\_gsm\_lic\_prmt.agency\_constituent\_agent\]Enables users to manage data for agencies in the constituent agent's agency hierarchy.- sn\_gsm.agency\_constituent\_agent - contract\_manager - decision\_table\_reader - sn\_gsm\_lic\_prmt.agency\_manager
License & Permit Agency Manager Contributor\[sn\_gsm\_lic\_prmt.agency\_manager\_contributor\]Enables users to create, update, view, and approve cases. They can also register and remove staff across all agencies they manage. - sn\_gsm\_lic\_prmt.business\_contributor - sn\_gsm\_lic\_prmt.agency\_relationship\_manager - sn\_gsm\_lic\_prmt.constituent\_contributor - sn\_gsm\_lic\_prmt.agency\_contributor - sn\_gsm\_lic\_prmt.agency\_manager\_core - sn\_gsm.agency\_manager\_contributor
License & Permits Agency Manager Core\[sn\_gsm\_lic\_prmt.agency\_manager\_core\]Granular role to manage agency staff registrations and staff relationships with businesses, constituents, and households for all the agencies within the hierarchy.- sn\_gsm.agency\_manager\_core - contract\_manager
License & Permit Agency Relationship Manager\[sn\_gsm\_lic\_prmt.agency\_relationship\_manager\]Enables users to view cases across all the external agencies where they have location\_relationship\_manager responsibility.- sn\_gsm.agency\_relationship\_manager - sn\_gsm\_lic\_prmt.agency\_manager\_contributor
License & Permit Case Task Agent\[sn\_gsm\_lic\_prmt.case\_task\_agent\]Provides users the ability to create and fulfill License & Permit cases for the constituents and households in the agent's agency.- sn\_gsm\_lic\_prmt.contributor\_editor - sn\_gsm\_lic\_prmt.case\_viewer - sn\_gsm.case\_task\_agent
License & Permit Case Viewer\[sn\_gsm\_lic\_prmt.case\_viewer\]This role provides users read only access to License & Permit case records.- sn\_gsm.case\_viewer - decision\_table\_reader - sn\_gsm\_lic\_prmt.case\_writer - sn\_gsm\_lic\_prmt.case\_task\_agent
License & Permit Agency Business Agent\[sn\_gsm\_lic\_prmt.agency\_agent\]Enables users to create and fulfill License & Permit cases for the accounts and contacts in the agent's agency.- sn\_gsm.agency\_agent - contract\_manager - decision\_table\_reader - sn\_gsm\_lic\_prmt.agency\_manager
License & Permit Business Agent\[sn\_gsm\_lic\_prmt.business\_agent\]Provides users the ability to work on license and permit cases for business. It includes the ability to read, write, or update all license and permit cases and business records.- sn\_gsm\_lic\_prmt.report\_viewer - sn\_gsm\_lic\_prmt.case\_writer - sn\_gsm.business\_agent - sn\_gsm\_lic\_prmt.ib\_viewer - sn\_gsm\_lic\_prmt.manager
License & Permits Install base admin\[sn\_gsm\_lic\_prmt.ib\_admin\]This role provides create,read,write, and delete access to Install base items.- sn\_gsm\_lic\_prmt.ib\_writer - sn\_gsm\_lic\_prmt.manager
License & Permits Case Writer\[sn\_gsm\_lic\_prmt.case\_writer\]This role provides users access to create, read and update License & Permits case records.- sn\_gsm\_lic\_prmt.case\_viewer - sn\_gsm.case\_writer - contract\_manager - sn\_gsm\_lic\_prmt.business\_agent - sn\_gsm\_lic\_prmt.constituent\_agent
License & Permits Agency Manager Core\[sn\_gsm\_lic\_prmt.agency\_manager\_core\]Granular role to manage agency staff registrations and staff relationships with businesses, constituents, and households for all the agencies within the hierarchy.- sn\_gsm.agency\_manager\_core - contract\_manager - sn\_gsm\_lic\_prmt.agency\_manager\_contributor - sn\_gsm\_lic\_prmt.agency\_manager
License & Permits Contributor Creator\[sn\_gsm\_lic\_prmt.contributor\_creator\]Enables users to create license and permit cases and is included in the top-level contributor roles. It only allows record creation but does not allow visibilty to a record on its own.- sn\_gsm.contributor\_creator - sn\_gsm\_lic\_prmt.agency\_contributor - sn\_gsm\_lic\_prmt.business\_contributor - sn\_gsm\_lic\_prmt.constituent\_contributor - sn\_gsm\_lic\_prmt.relationship\_contributor
License & Permit Constituent contributor\[sn\_gsm\_lic\_prmt.constituent\_contributor\]This role enables users to request for service and raise License & Permit cases on behalf of any constituent. This allow business stakeholders to act as a requestor on of behalf of customers.- sn\_gsm.constituent\_contributor - sn\_gsm\_lic\_prmt.contributor\_creator - sn\_gsm\_lic\_prmt.agency\_manager\_contributor
License & Permit Business Contributor\[sn\_gsm\_lic\_prmt.business\_contributor\]This role enables users to request for service and raise License & Permit cases on behalf of any business. This allow business stakeholders to act as a requester on of behalf of customers.- sn\_gsm.business\_contributor - sn\_gsm\_lic\_prmt.contributor\_creator - sn\_gsm\_lic\_prmt.agency\_manager\_contributor
License & Permit Relationship Contributor\[sn\_gsm\_lic\_prmt.relationship\_contributor\]Enables users to raise License & Permit cases on behalf of customers with whom they have relationships. This allows business stakeholder access to act as a requester on behalf of customers.- sn\_gsm.relationship\_contributors - n\_gsm\_lic\_prmt.contributor\_creator
License & Permit Contributor Editor\[sn\_gsm\_lic\_prmt.contributor\_editor\]Grants restrictive write access to the fields on the License and Permit Case form.- sn\_gsm.contributor\_creator - sn\_gsm\_lic\_prmt.case\_task\_agent
License & Permit Agency Contributor\[sn\_gsm\_lic\_prmt.agency\_contributor\]Enables users to request service and raise License & Permit cases for their service organization \(business location\). This role is agnostic to internal and external.- sn\_gsm.agency\_contributor - sn\_gsm\_lic\_prmt.contributor\_creator - sn\_gsm\_lic\_prmt.agency\_manager\_contributor
Role title \[name\]DescriptionContains roles
Social Benefits Case Viewer\[sn\_gsm\_soc\_bnfts.case\_viewer\]This role provides users read only access to Social Benefits Case records.- sn\_gsm.case\_viewer - decision\_table\_reader
Social Benefits Case Writer\[sn\_gsm\_soc\_bnfts.case\_writer\]This role provides users access to create, read and update Social Benefits Case records.- sn\_gsm\_soc\_bnfts.case\_viewer - sn\_gsm.case\_writer - contract\_manager
Social Benefits install base admin\[sn\_gsm\_soc\_bnfts.ib\_admin\]This role provides create,read,write, and delete access to Install base items.sn\_gsm\_soc\_bnfts.ib\_writer
Social Benefits install base read granular\[sn\_gsm\_soc\_bnfts.ib\_read\_granular\]Provides granular read access to issued Social Benefits.sn\_install\_base.install\_base\_read\_granular
Social Benefits install base viewer\[sn\_gsm\_soc\_bnfts.ib\_viewer\]Provides read access to Install base items.None
Social Benefits install base writer\[sn\_gsm\_soc\_bnfts.ib\_writer\]Provides create, read and write access to Install base items.sn\_gsm\_soc\_bnfts.ib\_viewer
Social Benefits Constituent Contributor\[sn\_gsm\_soc\_bnfts.constituent\_contributor\]This role enables users to request service and raise Social Benefits cases on behalf of any constituent. This allows business stakeholders to act as a requestor on behalf of customers.- sn\_gsm.constituent\_contributor - sn\_gsm\_soc\_bnfts.contributor\_creator
Social Benefits Contributor Creator\[sn\_gsm\_soc\_bnfts.contributor\_creator\]Enables users to create Social Benefits cases and is included in the top-level contributor roles. It only allows record creation but does not allow visibility to a record on its own.- sn\_gsm.constituent\_contributor - sn\_gsm\_soc\_bnfts.contributor\_creator
Social Benefits Contributor Editor\[sn\_gsm\_soc\_bnfts.contributor\_editor\]Grants restrictive write access to the fields on the Social Benefits Case form.sn\_gsm.contributor\_creator
Social Benefits Relationship Contributor\[sn\_gsm\_soc\_bnfts.relationship\_contributor\]Enables users to raise Social Benefits cases on behalf of customers with whom they have relationships. This allows business stakeholder access to act as a requester on behalf of customers.- sn\_gsm.relationship\_contributor - sn\_gsm\_soc\_bnfts.contributor\_creator
social\_benefits\_agency\_agent\[sn\_gsm\_soc\_bnfts.agency\_agent\]Provides users the ability to create and fulfill cases for the accounts and contacts in the agent's agency.- sn\_gsm.agency\_agent - decision\_table\_reader - contract\_manager
social\_benefits\_agency\_constituent\_agent\[sn\_gsm\_soc\_bnfts.agency\_constituent\_agent\]Provides users the ability to create and fulfill cases for the constituents and households in the agent's agency.- decision\_table\_reader - sn\_gsm.agency\_constituent\_agent - contract\_manager
social\_benefits\_agency\_contributor\[sn\_gsm\_soc\_bnfts.agency\_contributor\]Enables users to request service and raise Social Benefits cases for their agency\(business location\). This role is agnostic to internal and external.- sn\_gsm.government\_agency\_contributor - sn\_gsm\_soc\_bnfts.contributor\_creator
social\_benefits\_agency\_manager\[sn\_gsm\_soc\_bnfts.agency\_manager\]Provides users the ability to manage data for agencies in the manager's agency hierarchy.- sn\_gsm\_soc\_bnfts.agency\_agent - sn\_gsm\_soc\_bnfts.agency\_manager\_core - sn\_gsm.agency\_manager - sn\_gsm\_soc\_bnfts.agency\_constituent\_agent
social\_benefits\_agency\_manager\_contributor\[sn\_gsm\_soc\_bnfts.agency\_manager\_contributor\]Manage agencies and create a case for a business, household, or constituent at the agency or any child agency.- sn\_gsm\_soc\_bnfts.agency\_contributor - sn\_gsm\_soc\_bnfts.business\_contributor - sn\_gsm\_soc\_bnfts.agency\_manager\_core - sn\_gsm\_soc\_bnfts.constituent\_contributor - sn\_gsm.agency\_manager\_contributor
social\_benefits\_agency\_manager\_core\[sn\_gsm\_soc\_bnfts.agency\_manager\_core\]Granular role to manage agency staff registrations and staff relationships with businesses, constituents, and households for all the agencies within the hierarchy.- sn\_gsm.agency\_manager\_core - contract\_manager
social\_benefits\_agency\_relationship\_manager\[sn\_gsm\_soc\_bnfts.agency\_relationship\_manager\]Manages and monitors all the activities performed by the agencies. It also acts as an internal point of contact for the agencies.- sn\_gsm\_soc\_bnfts.agency\_manager\_contributor - sn\_gsm.agency\_relationship\_manager
social\_benefits\_business\_agent\[sn\_gsm\_soc\_bnfts.business\_agent\]Provides users the ability to work on Social Benefits cases for business. It includes the ability to read/write/update all Social Benefits cases and business records.- sn\_gsm\_soc\_bnfts.case\_writer - sn\_gsm\_soc\_bnfts.report\_viewer - sn\_gsm.business\_agent - sn\_gsm\_soc\_bnfts.ib\_viewer
Social Benefits Case Task Agent\[sn\_gsm\_soc\_bnfts.case\_task\_agent\]Enables users to work on Social Benefits case tasks.- sn\_gsm\_soc\_bnfts.case\_viewer - sn\_gsm\_soc\_bnfts.contributor\_editor - sn\_gsm.case\_task\_agent
Social Benefits Constituent Agent\[sn\_gsm\_soc\_bnfts.constituent\_agent\]Provides users the ability to work on Social Benefits cases for all constituents. It includes the ability to read/write/update all cases and constituent records- sn\_gsm\_soc\_bnfts.case\_writer - sn\_gsm\_soc\_bnfts.report\_viewer - sn\_gsm.constituent\_agent - sn\_gsm\_soc\_bnfts.ib\_viewer
Social Benefits Manager\[sn\_gsm\_soc\_bnfts.manager\]Provides users the ability to manage all work performed by agents working on Social Benefits cases \(constituent and business\). Users with this role have the ability to read/write/update/delete all Social Benefits cases and constituent/business records.- sn\_gsm\_soc\_bnfts.ib\_admin - sn\_gsm\_soc\_bnfts.business\_agent - sn\_gsm.government\_service\_manager - sn\_gsm\_soc\_bnfts.constituent\_agent - sn\_majorissue\_mgt.major\_issue\_manager
Social Benefits Relationship Agent\[sn\_gsm\_soc\_bnfts.relationship\_agent\]Enables users to work on Social Benefits cases only for customers with whom they have relationships.- sn\_gsm\_soc\_bnfts.report\_viewer - decision\_table\_reader - sn\_gsm.relationship\_agent - contract\_manager
Role title \[name\]DescriptionContains roles
Adminsn\_gsm\_info\_req.adminProvides delegated admin access to scoped applications created on the Information Request Playbook platform.- sn\_gsm\_info\_req.manager - sn\_gsm.admin
Agency Agentsn\_gsm\_info\_req.agency\_agentProvides users the ability to create and fulfill cases for the accounts and contacts in the agent's agency.sn\_gsm.agency\_agent
Agency Constituent Agentsn\_gsm\_info\_req.agency\_constituent\_agentProvides users the ability to create and fulfill cases for the constituents and households in the agent's agency.sn\_gsm.agency\_constituent\_agent
Agency Contributorsn\_gsm\_info\_req.agency\_contributorEnables users to request service and raise Information Request cases for their service organization \(business location\).- sn\_gsm\_info\_req.contributor\_creator - sn\_gsm.government\_agency\_contributor
Agency Managersn\_gsm\_info\_req.agency\_managerProvides users the ability to manage data for agencies in the manager's agency hierarchy.- sn\_gsm\_info\_req.agency\_constituent\_agent - sn\_gsm.agency\_manager - sn\_gsm\_info\_req.agency\_agent
Business Agentsn\_gsm\_info\_req.business\_agentProvides users the ability to work on Information Request cases for business. It includes the ability to read, write, and update all Information Request cases and business records.- sn\_gsm.business\_agent - sn\_gsm\_info\_req.case\_writer - sn\_gsm\_info\_req.report\_viewer
Business Contributorsn\_gsm\_info\_req.business\_contributorEnables users to request for service and raise Information Request cases on behalf of any business. This allow business stakeholders to act as a requester on of behalf of customers.- sn\_gsm\_info\_req.contributor\_creator - sn\_gsm.business\_contributor
Case Task Agentsn\_gsm\_info\_req.case\_task\_agentEnables users to work on Information Request case tasks.- sn\_gsm\_info\_req.case\_viewer - sn\_gsm.case\_task\_agent - sn\_gsm\_info\_req.contributor\_editor
Case Viewersn\_gsm\_info\_req.case\_viewerProvides users read only access to Information Request Case records.sn\_gsm.case\_viewer
Case Writersn\_gsm\_info\_req.case\_writerProvides users access to create read and update Information Request Case records.- sn\_gsm.case\_writer - sn\_gsm\_info\_req.case\_viewer
Constituent Agentsn\_gsm\_info\_req.constituent\_agentProvides users the ability to work on Information Request cases for all constituents. It includes the ability to read, write, and update all Information Request cases and constituent records.- sn\_gsm\_info\_req.case\_writer - sn\_gsm\_info\_req.report\_viewer - sn\_gsm.constituent\_agent
Constituent Contributorsn\_gsm\_info\_req.constituent\_contributorEnables users to request for service and raise Information Request cases on behalf of any constituent. This allows business stakeholders to act as a requestor on behalf of customers.- sn\_gsm\_info\_req.contributor\_creator - sn\_gsm.constituent\_contributor
Contributor Creatorsn\_gsm\_info\_req.contributor\_creatorEnables users to create Information Request cases and is included in the top-level contributor roles. It only allows record creation but does not allow visibility to a record on its own.sn\_gsm.contributor\_creator
Contributor Editorsn\_gsm\_info\_req.contributor\_editorGrants restrictive write access to the fields on the Information Request Case form.sn\_gsm.contributor\_editor
Request Managersn\_gsm\_info\_req.managerProvides users the ability to manage all work performed by agents working on Information Request cases \(constituent and business\). Users with this role have the ability to read, write, update, and delete all Information Request service cases and constituent or business records.- sn\_majorissue\_mgt.major\_issue\_manager - sn\_gsm\_info\_req.business\_agent - sn\_gsm.government\_service\_manager - sn\_gsm\_info\_req.constituent\_agent
Relationship Agentsn\_gsm\_info\_req.relationship\_agentEnables users to work on Information Request cases only for customers with whom they have relationships.- sn\_gsm.relationship\_agent - sn\_gsm\_info\_req.report\_viewer
Relationship Contributorsn\_gsm\_info\_req.relationship\_contributorEnables users to raise Information Request cases on behalf of customers with whom they have relationships. This allows business stakeholder access to act as a requester on behalf of customers.- sn\_gsm.relationship\_contributor - sn\_gsm\_info\_req.contributor\_creator
Report Viewersn\_gsm\_info\_req.report\_viewerProvides users access to view reports containing Information Request data.sn\_gsm.report\_viewer
Role title \[name\]DescriptionContains roles
Program Admin \(sn\_svc\_appl\_pgm\_mg.admin\)Provides delegated admin access to scoped applications created on the Service Applicant Program Management platformNone
Grant Program Admin \(sn\_svc\_appl\_pgm\_mg.grant\_program\_admin\)Provides access to all Grant Programs.sn\_svc\_appl\_pgm\_mg.grant\_program\_writer
Grant Program Director \(sn\_svc\_appl\_pgm\_mg.grant\_program\_director\)Provides access to all Grant Programs.- sn\_gsm.government\_service\_manager - sn\_svc\_appl\_pgm\_mg.grant\_program\_manager
Grant Program Writer \(sn\_svc\_appl\_pgm\_mg.grant\_program\_manager\)Creates or updates Grant Programs if they are a part of.- sn\_gsm.business\_agent - sn\_svc\_appl\_pgm\_mg.grant\_program\_writer - sn\_smart\_asmt.assessment\_admin - sn\_svc\_appl\_pgm\_mg.planning\_item\_writer - sn\_svc\_appl\_pgm\_mg.resource\_mapping\_writer - sn\_svc\_appl\_pgm\_mg.scoring\_framework\_writer - sn\_svc\_appl\_pgm\_mg.resource\_assignment\_writer - sn\_svc\_appl\_pgm\_mg.milestone\_writer - sn\_svc\_appl\_pgm\_mg.resource\_role\_writer - sn\_gsm.goal\_viewer - sn\_svc\_appl\_pgm\_mg.business\_calendar\_entry\_viewer - sn\_svc\_appl\_pgm\_mg.pace\_reader - sn\_pace.mapping\_admin - sn\_svc\_appl\_pgm\_mg.scoring\_framework\_attribute\_writer
Grant Program Viewer \(sn\_svc\_appl\_pgm\_mg.grant\_program\_writer\)Provides write access to Grant Program records.- sn\_svc\_appl\_pgm\_mg.grant\_program\_viewer - sn\_svc\_appl\_pgm\_mg.planning\_item\_writer
Planning Item Writer \(sn\_svc\_appl\_pgm\_mg.grant\_program\_viewer\)Provides read access to Grant Program records.sn\_svc\_appl\_pgm\_mg.planning\_item\_viewer
Planning Item Viewer \(sn\_svc\_appl\_pgm\_mg.planning\_item\_writer\)Provides write access to Planning Item records.sn\_svc\_appl\_pgm\_mg.planning\_item\_viewer
Budget Allocation Writer \(sn\_svc\_appl\_pgm\_mg.planning\_item\_viewer\)Provides read access to Planning Item records.None
\(sn\_svc\_appl\_pgm\_mg.budget\_allocation\_writer\)Provides write access to Budget Allocation records.sn\_svc\_appl\_pgm\_mg.budget\_allocation\_viewer
\(sn\_svc\_appl\_pgm\_mg.budget\_allocation\_viewer\)Provides read access to Budget Allocation records.None
\(sn\_svc\_appl\_pgm\_mg.milestone\_writer\)Provides write access to Milestone records.sn\_svc\_appl\_pgm\_mg.milestone\_viewer
\(sn\_svc\_appl\_pgm\_mg.milestone\_viewer\)Provides read access to Milestone records.None
Resource Assignment Writer \(sn\_svc\_appl\_pgm\_mg.resource\_assignment\_writer\)Provides write access to Resource Assignment records.sn\_svc\_appl\_pgm\_mg.resource\_assignment\_viewer
Resource Assignment Viewer \(sn\_svc\_appl\_pgm\_mg.resource\_assignment\_viewer\)Provides read access to Resource Assignment records.None
Informational Resource Mapping Writer \(sn\_svc\_appl\_pgm\_mg.resource\_mapping\_writer\)Provides write access to Informational Resource Mapping records.sn\_svc\_appl\_pgm\_mg.resource\_mapping\_viewer
Informational Resource Mapping Viewer \(sn\_svc\_appl\_pgm\_mg.resource\_mapping\_viewer\)Provides read access to Informational Resource Mapping records.None
Resource Role Writer \(sn\_svc\_appl\_pgm\_mg.resource\_role\_writer\)Provides write access to Resource Role records.sn\_svc\_appl\_pgm\_mg.resource\_role\_viewer
Resource Role Viewer \(sn\_svc\_appl\_pgm\_mg.resource\_role\_viewer\)Provides read access to Resource Role records.None
Scoring Framework Writer \(sn\_svc\_appl\_pgm\_mg.scoring\_framework\_writer\)Provides write access to Scoring Framework records.sn\_svc\_appl\_pgm\_mg.scoring\_framework\_viewer
Scoring Framework Viewer \(sn\_svc\_appl\_pgm\_mg.scoring\_framework\_viewer\)Provides read access to Scoring Framework records.None
Scoring Framework Attribute Writer \(sn\_svc\_appl\_pgm\_mg.scoring\_framework\_attribute\_writer\)Provides write access to Scoring Framework Attributes records.sn\_svc\_appl\_pgm\_mg.scoring\_framework\_attribute\_viewer
Scoring Framework Attribute Viewer \(sn\_svc\_appl\_pgm\_mg.scoring\_framework\_attribute\_viewer\)Provides read access to Scoring Framework Attributes records.None
Business Calendar Entry Viewer \(sn\_svc\_appl\_pgm\_mg.business\_calendar\_entry\_viewer\)Provides read access to Business Calendar Entry and Business Calendar Entry Name tables.None
Pace Reader \(sn\_svc\_appl\_pgm\_mg.pace\_reader\)Provides read access to PaCE records.None
Report Viewer \(sn\_svc\_appl\_pgm\_mg.report\_viewer\)Provides users the access to view reports of Program records.None

Roles by Plugin

Role title \[name\]DescriptionContains roles
\(sn\_svc\_appl\_info.admin\)Provides delegated admin access to scoped applications created on the Service Application Information.- sn\_svc\_appl\_info.point\_in\_time\_content\_admin - sn\_svc\_appl\_info.applicant\_admin - sn\_svc\_appl\_info.financial\_details\_admin
\(sn\_svc\_appl\_info.applicant\_admin\)Provides create,read,write and delete access to applicant records.sn\_svc\_appl\_info.applicant\_writer
\(sn\_svc\_appl\_info.applicant\_viewer\)Provides read access to applicant records. 
\(sn\_svc\_appl\_info.applicant\_writer\)Provides create,read and write access to applicant records.sn\_svc\_appl\_info.applicant\_viewer
\(sn\_svc\_appl\_info.financial\_details\_admin\)Provides create,read,write and delete access to financial details records.sn\_svc\_appl\_info.financial\_details\_writer
\(sn\_svc\_appl\_info.financial\_details\_viewer\)Provides read access to financial details records.None
\(sn\_svc\_appl\_info.financial\_details\_writer\)Provides create,read and write access to financial details records.sn\_svc\_appl\_info.financial\_details\_viewer
\(sn\_svc\_appl\_info.point\_in\_time\_content\_admin\)Provides create,read, write and delete access to point-in-time content records.sn\_svc\_appl\_info.point\_in\_time\_content\_writer
\(sn\_svc\_appl\_info.point\_in\_time\_content\_viewer\)Provides read access to point-in-time content records.None
\(sn\_svc\_appl\_info.point\_in\_time\_content\_writer\)Provides create,read and write access to point-in-time content records.sn\_svc\_appl\_info.point\_in\_time\_content\_viewer
\(sn\_svc\_appl\_info.report\_viewer\)Provides users the access to view reports on the Service Applicant Information platform.None
RoleDescriptionPersona
sn_pace.execution_readerA read-only user with view-only access. This user can view policies, categories, and executions.Policy user, internal auditor.
sn_pace.code_readerCan review PaCE versions, policy code, and run tests.Internal auditor
sn_pace.code_editorThis user has all the sn_pace_code_reader permissions plus the ability to create PaCE policy versions.Policy developer
sn_pace.policy_readerThis user has all the sn_pace_code_reader permissions plus the ability to review policy details and mapping information.Policy user, internal auditor
sn_pace.policy_editorThis user has all the sn_pace_policy_reader and sn_pace.code_editor permissions plus the ability to create policies and mappings.Policy developer
sn_pace.mapping_adminThis user can map policies and edit config parameters for policy mappings.Mapping admin
sn_pace.adminThis user has the permissions of all the other roles plus the ability to create categories, policies, mappings, and code.Policy admin
sn_pace.super_adminThis user has all the sn_pace.admin role permissions across all calling services.Not applicable
Maint roleInternal user who can create default content.Not applicable

Granular roles

You can use predefined functional and granular roles installed with Public Sector Digital Services to establish relationships between users and public sector entities. These functional and granular roles provide different levels of access to public sector data.

  • Functional roles: A set of roles required to perform a function or meaningful action that requires access on multiple entities.
  • Granular roles: Roles that provide access to cases, services used, and related public sector entities. One or more granular roles can be bundled together as a functional role.

A granular model controls access to data through UI-based interactions by granting the appropriate level of access to the corresponding public sector entities. With this functionality, each role is associated with a set of privileges or responsibilities that determine users' access to information via forms, lists, and application features. You can have fine-grained access control by setting granular policies that authorize individuals to access the information needed to work efficiently and effectively, ultimately helping improve the constituent experience.

Note: Role-based access controls govern UI interactions. They do not restrict access by users with system-level scripting privileges or elevated platform roles. These roles control access to public sector data through UI-based features such as forms and lists.

For example, if you extend the Government Service Case table or other tables in the Public Sector Digital Services app, you must replicate the access control lists for the extended tables. You can assign granular roles to public sector users to control access to those extended tables.

Role title \[name\]DescriptionContains roles
case\_create\_granular\[sn\_gsm.case\_create\_granular\]Provides constituents or business stakeholders with granular create access to government service cases.sn\_gsm.case\_read\_granular
case\_read\_granular\[sn\_gsm.case\_read\_granular\]Provides constituents or business stakeholders with granular read access to government service cases.sn\_customerservice.case\_read\_granular
case\_write\_granular\[sn\_gsm.case\_write\_granular\]Provides constituents or business stakeholders with granular write access to government service cases.- sn\_gsm.case\_create\_granular - sn\_gsm.case\_read\_granular
service\_received\_read\_granular\[sn\_gsm.service\_received\_read\_granular\]Provides constituents or business stakeholders with granular read access to services-received records.sn\_install\_base.sold\_product\_read\_granular
License & Permits Install base read granular\[sn\_gsm\_lic\_prmt.ib\_read\_granular\]Provides granular read access to issued License and Permits.- sn\_install\_base.install\_base\_read\_granular - sn\_gsm.business\_contact - sn\_gsm.constituent
case\_admin\[sn\_gsm\_icm.case\_admin\]Provides read and write access to all the investigative cases.- sn\_gsm\_icm.case\_writer - sn\_gsm\_icm.case\_viewer - sn\_gsm\_icm.event\_writer - sn\_gsm\_icm.entity\_writer - sn\_gsm\_icm.report\_viewer

Business Stakeholder Roles

Business Stakeholder for Public Sector Digital Services includes plugins and roles that provide access to business stakeholder features.

Admins with access to Business Stakeholder can provide Business Stakeholder users with the rights to the following actions:

  • Create cases on behalf of a business or an agency (service organization)
  • View cases, case tasks, and business data.
  • Approve requests.
RoleDescriptionContains rolesPluginUser type
Constituent contributor\[sn\_gsm.constituent\_contributor\]Enables users to request services and raise government service cases on behalf of any constituent.- sn\_customerservice.consumer\_contributor - sn\_gsm.contributor\_creatorcom.sn\_public\_sector\_digital\_services\_coreInternal and external
Business contributor\[sn\_gsm.business\_contributor\]Enables business stakeholders to request services and raise government service cases on behalf of any business.- sn\_customerservice.relationship\_contributor - sn\_gsm.contributor\_creatorcom.sn\_public\_sector\_digital\_services\_coreinternal and external
Relationship contributor\[sn\_gsm.relationship\_contributor\]Enables business stakeholders to raise government service cases on behalf of customers with which they have a relationship.- sn\_customerservice.relationship\_contributor - sn\_gsm.contributor\_creatorcom.sn\_public\_sector\_digital\_services\_coreInternal and external
RoleDescriptionContains rolesPluginUser type
Agency contributor\[sn\_gsm.agency\_contributor\]Enables agency agents to request services and raise government service cases on behalf of the agency.- sn\_customerservice.service\_organization\_contributor - sn\_gsm.contributor\_creatorAgency Support Model \(com.sn\_agency\_support\_model\)Internal and external
Social Benefits Business Contributor\[sn\_gsm\_soc\_bnfts.business\_contributor\]Enables users to request service and raise Social Benefits cases on behalf of any business. This allows business stakeholders to act as a requester on behalf of customers.- sn\_gsm.business\_contributor - sn\_gsm\_soc\_bnfts.contributor\_creator  
RoleDescriptionContains rolesPluginUser type
Case viewer\[sn\_gsm.case\_viewer\]Provides agents with read-only access to government service cases.Nonecom.sn\_public\_sector\_digital\_services\_coreInternal
Constituent viewer\[sn\_gsm.constituent\_viewer\]Provides agents with read-only access to constituent records.sn\_customerservice.customer\_data\_viewercom.sn\_public\_sector\_digital\_services\_coreInternal
Business viewer\[sn\_gsm.business\_viewer\] Nonecom.sn\_public\_sector\_digital\_services\_coreInternal
Services offered viewer\[sn\_gsm.service\_offered\_viewer\]Provides users with read-only access to services offered records and services received records.sn\_customerservice.customer\_data\_viewercom.sn\_public\_sector\_digital\_services\_coreInternal
Government services received viewer\[sn\_gsm.service\_received\_viewer\]Provides users with read-only access to services received records.Nonecom.sn\_public\_sector\_digital\_services\_coreInternal
RoleDescriptionContains roles
report\_viewer\[sn\_gsm.report\_viewer\]Enables users to view reports on the Public Sector Digital Services platform.None
grant\_management\_report\_viewersn\_gsm\_grnt\_mgmt.report\_viewerEnables users to view reports about the grants management playbooks.sn\_gsm.report\_viewer
License & Permit Report Viewer\[sn\_gsm\_lic\_prmt.report\_viewer\]Enables users to view reports on the Public Sector Digital Services platform.sn\_gsm.report\_viewer
social\_benefit\_report\_viewer\[sn\_gsm\_soc\_bnfts.report\_viewer\]Provides users access to view reports Social Benefits Playbook.sn\_gsm.report\_viewer
\(sn\_svc\_appl\_info.report\_viewer\)Provides users the access to view reports on the Service Applicant Information platform.None

Note: Customers who have purchased a Public Sector Digital Services subscription can provide Business Stakeholder users with rights to actions listed under Business Stakeholder for Customer Service Management.

Parent Topic:Components and Roles installed with Public Sector Digital Services Core