RegalGovOperating Playbook
Regal Governance · Customer Documentation

Know who does what. Know who approves.

A practical operating guide for responsibilities, approvals, segregation of duties, scope and accountability across Regal Governance.

One operating principleRegal separates the person who prepares a protected action from the person who independently approves it whenever governance requires that control.
No matching responsibility or process found.
Responsibility model

Who owns what

Regal uses business personas and independent controls instead of giving one administrator unrestricted authority.

IT
Tenant administration

Tenant IT Admin

Creates identities, manages technical access, sessions and permitted tenant configuration. Business-data blind by default.

G
Policy owner

Governance Admin

Prepares governance, approval and SoD rules. Does not automatically gain transaction authority.

M
Functional ownership

Managers & Approvers

Own business processes and approve within assigned persona, company, branch and business-unit scope.

P
Maker

Processors & Preparers

Sales reps, officers, clerks, engineers and accountants prepare or execute work within granted authority.

C
Independent oversight

Compliance

Reviews governance evidence, violations and audit trails without becoming the transaction processor.

R
Platform boundary

Regal Platform Admin

Operates the platform technically. Platform privilege is not customer business authority.

People & access

How a user gets authority

Creating a login and granting business authority are intentionally different actions.

STEP 1
Create identityTenant IT creates the backend user.
STEP 2
Request personaAuthorized administration selects business responsibility.
STEP 3
Independent approvalMaker and target user cannot self-approve the protected grant.
STEP 4
Activate with scopeCompany, branch and BU scope constrain effective access.
Regal control:

A newly created backend identity remains inactive until its initial persona assignment is independently approved. Protected SYS_ADMIN, GOV_ADMIN and TECH_SUPPORT provisioning follows a specially controlled path.

Policy configuration

Who sets the rules

Governance configuration itself is governed. A rule change is not automatically live because an administrator typed it.

Prepare

Governance Admin

Creates or materially changes approval levels, discount limits, margin controls, pricing authority, field visibility, SLAs, transaction conditions, release conditions and escalation behavior.

Approve activation

Independent Governance / Executive Authority

A different eligible authority approves activation where maker/checker applies. Human-created or changed protected rules remain disabled until approval.

SoD

Conflict rules

Critical and High non-overridable conflicts remain blocked where defined.

Exceptions

Independent exception approval

The target user and the request creator cannot approve the same protected exception.

Delegation

Delegated authority is still checked

Effective delegated personas are included in SoD evaluation before activation.

Company processes

Who starts, reviews and approves

Open a process to see the responsibility chain and the control Regal applies.

Sales · CRM, quotation & sales order
Owner: Sales management
+
StartsSales Rep
Technical inputEngineer / Technical Sales
ReviewsSales Manager
Higher approvalBranch Manager / BU Leader / configured authority
Regal enforces: pricing, discount, margin, approval and scope rules can stop confirmation or release until the required authority approves.
Procurement · Procure-to-Pay
Owner: Procurement + Finance
+
Purchase orderPurchase Officer → Purchase Manager
Goods receiptLogistics / Warehouse
Vendor billAP / Accountant → Accounting authority
PaymentTreasury → Finance approval chain
Regal enforces: procurement, receipt, AP processing and payment execution are separated where required. Master-data makers cannot certify their own protected changes.
Finance · Accounting, partner & bank master
Owner: Finance
+
ProcessesAccountant / AP Clerk / AR Clerk
ValidatesChief Accountant / Financial Controller
OversightCFO
Executes paymentTreasury Officer
Regal enforces: new or materially changed bank accounts and sensitive partner master changes remain untrusted until independently validated. CFO oversight does not automatically grant payment execution.
Inventory & Logistics · Stock movement and adjustment
Owner: Logistics / Warehouse
+
ProcessesLogistics Clerk / stock operator
ManagesLogistics / Warehouse Manager
Adjustment approvalIndependent governance / authorized approver
Branch transfersAuthorized send/receive actors
Regal enforces: inventory adjustment follows Prepare → Independent Approval → Adjust. Actual validator/receiver and transfer states remain auditable.
HR & Attendance · Employees and ground workforce
Owner: HR
+
Employee adminHR Officer
ManagesHR Manager
Attendance identityAuthorized HR
Ground employeeCheck in/out by attendance identity/PIN
Regal enforces: ground workers do not need normal backend accounts merely for attendance. HR administration does not automatically expose payroll compensation or bank information.
Payroll · Prepare, validate, approve & pay
Owner: Payroll + Finance
+
PreparesPayroll Officer
ValidatesPayroll Manager
ApprovesRequired independent Finance / Executive authority
ExecutesTreasury Officer
Regal enforces: preparation, validation, approval and payment execution are separately recorded. Treasury uses payment execution authority without needing employee salary-detail authority.
Projects & Technical · Delivery and budget changes
Owner: Project / BU management
+
Technical workEngineer
ManagesProject Manager
Budget controlBU Leader / Cost Controller / configured authority
Commercial triggerApproved CRM / sales process where applicable
Regal enforces: technical execution does not grant unrelated finance/payment authority. Governed budget changes require approval instead of silent modification.
Reporting, KPI & Audit
Owner: Functional owners + Governance
+
Operational reportsFunctional personas in own scope
KPIRelevant functional / executive persona
AuditCompliance / Governance
IT AdminSystem/IT metrics only where defined
Regal enforces: reporting does not bypass record access, confidentiality, branch/BU scope or IT-admin blindness.
Control model

Approval is a control, not a status

A protected action remains blocked until the required approval is satisfied.

1 · Maker

Who initiated it?

The system records the requestor or actor who created or changed the controlled item.

2 · Policy

Why is approval required?

The applicable governance rule, authority threshold, SoD control or protected lifecycle action is explicit.

3 · Checker

Who can approve?

An independent eligible authority within the required persona and organizational scope.

4 · Evidence

What is recorded?

Actor, time, decision, source record, scope, comments and escalation evidence.

5 · Escalation

What if overdue?

Configured escalation identifies who becomes responsible and records the event.

6 · Release

What happens after approval?

Only then does the protected confirmation, activation, posting, adjustment or release become available.

Scalable governance

One authority model, different company sizes

Regal can consolidate compatible responsibilities for smaller organizations without silently removing critical controls.

Highest segregation

Enterprise / Strict

Specialized roles and strong maker/checker separation across critical chains.

Balanced

Standard / Segregated

Managers may hold several responsibilities while critical activities remain independently checked.

Small company

Compact / Controlled

Compatible responsibilities may combine, but compensating independent approval remains explicit and auditable.

Exceptional

Single-Operator

Technical convenience never silently removes protected control evidence or mandatory independence.

Compact is not a waiver profile.

Combining responsibilities does not mean bypassing governance. Regal uses the same authority model and applies compensating independent approval where consolidation is permitted.

Quick reference

Who can do what?

This customer responsibility map shows the normal maker, checker and policy owner. Actual access still depends on assigned persona and scope.

ActivityMaker / ResponsibleChecker / ApproverPolicy Owner
Create tenant user identityTenant ITIndependent persona approval before activationGovernance / Tenant management
Assign or change personaAuthorized adminIndependent approverGovernance Admin
Configure governance / SoD ruleGovernance AdminDifferent Governance / Executive authorityGovernance Admin
Request SoD exceptionAuthorized requesterIndependent eligible approverGovernance / Compliance
Prepare quotationSales Rep / Technical Sales where applicableSales Manager / threshold authoritySales management
Prepare purchase orderPurchase OfficerPurchase ManagerProcurement management
Receive goodsLogistics / WarehouseIndependent control where requiredLogistics management
Process vendor billAP / AccountantChief Accountant / Financial ControllerFinance
Execute supplier paymentTreasuryFinance approval chainCFO / Finance control
Maintain bank accountAuthorized finance / payroll maintainerIndependent bank validatorFinance / Payroll governance
Maintain partner / product masterAuthorized master-data makerIndependent master validatorFunctional owner / Governance
Adjust inventoryAuthorized stock makerIndependent approvalLogistics / Governance
Maintain employee dataHR OfficerHR Manager where requiredHR
Prepare payrollPayroll OfficerPayroll Manager / further approvalPayroll / Finance
Execute payroll paymentTreasuryRequired independent payroll approval already completedFinance
Manage projectProject ManagerBU / budget authority where requiredOperations / BU
Review audit / violationsCompliance / GovernanceOversightGovernance