Who owns what
Regal uses business personas and independent controls instead of giving one administrator unrestricted authority.
Tenant IT Admin
Creates identities, manages technical access, sessions and permitted tenant configuration. Business-data blind by default.
Governance Admin
Prepares governance, approval and SoD rules. Does not automatically gain transaction authority.
Managers & Approvers
Own business processes and approve within assigned persona, company, branch and business-unit scope.
Processors & Preparers
Sales reps, officers, clerks, engineers and accountants prepare or execute work within granted authority.
Compliance
Reviews governance evidence, violations and audit trails without becoming the transaction processor.
Regal Platform Admin
Operates the platform technically. Platform privilege is not customer business authority.
How a user gets authority
Creating a login and granting business authority are intentionally different actions.
A newly created backend identity remains inactive until its initial persona assignment is independently approved. Protected SYS_ADMIN, GOV_ADMIN and TECH_SUPPORT provisioning follows a specially controlled path.
Who sets the rules
Governance configuration itself is governed. A rule change is not automatically live because an administrator typed it.
Governance Admin
Creates or materially changes approval levels, discount limits, margin controls, pricing authority, field visibility, SLAs, transaction conditions, release conditions and escalation behavior.
Independent Governance / Executive Authority
A different eligible authority approves activation where maker/checker applies. Human-created or changed protected rules remain disabled until approval.
Conflict rules
Critical and High non-overridable conflicts remain blocked where defined.
Independent exception approval
The target user and the request creator cannot approve the same protected exception.
Delegated authority is still checked
Effective delegated personas are included in SoD evaluation before activation.
Who starts, reviews and approves
Open a process to see the responsibility chain and the control Regal applies.
Sales · CRM, quotation & sales orderOwner: Sales management+
Procurement · Procure-to-PayOwner: Procurement + Finance+
Finance · Accounting, partner & bank masterOwner: Finance+
Inventory & Logistics · Stock movement and adjustmentOwner: Logistics / Warehouse+
HR & Attendance · Employees and ground workforceOwner: HR+
Payroll · Prepare, validate, approve & payOwner: Payroll + Finance+
Projects & Technical · Delivery and budget changesOwner: Project / BU management+
Reporting, KPI & AuditOwner: Functional owners + Governance+
Approval is a control, not a status
A protected action remains blocked until the required approval is satisfied.
Who initiated it?
The system records the requestor or actor who created or changed the controlled item.
Why is approval required?
The applicable governance rule, authority threshold, SoD control or protected lifecycle action is explicit.
Who can approve?
An independent eligible authority within the required persona and organizational scope.
What is recorded?
Actor, time, decision, source record, scope, comments and escalation evidence.
What if overdue?
Configured escalation identifies who becomes responsible and records the event.
What happens after approval?
Only then does the protected confirmation, activation, posting, adjustment or release become available.
One authority model, different company sizes
Regal can consolidate compatible responsibilities for smaller organizations without silently removing critical controls.
Enterprise / Strict
Specialized roles and strong maker/checker separation across critical chains.
Standard / Segregated
Managers may hold several responsibilities while critical activities remain independently checked.
Compact / Controlled
Compatible responsibilities may combine, but compensating independent approval remains explicit and auditable.
Single-Operator
Technical convenience never silently removes protected control evidence or mandatory independence.
Combining responsibilities does not mean bypassing governance. Regal uses the same authority model and applies compensating independent approval where consolidation is permitted.
Who can do what?
This customer responsibility map shows the normal maker, checker and policy owner. Actual access still depends on assigned persona and scope.
| Activity | Maker / Responsible | Checker / Approver | Policy Owner |
|---|---|---|---|
| Create tenant user identity | Tenant IT | Independent persona approval before activation | Governance / Tenant management |
| Assign or change persona | Authorized admin | Independent approver | Governance Admin |
| Configure governance / SoD rule | Governance Admin | Different Governance / Executive authority | Governance Admin |
| Request SoD exception | Authorized requester | Independent eligible approver | Governance / Compliance |
| Prepare quotation | Sales Rep / Technical Sales where applicable | Sales Manager / threshold authority | Sales management |
| Prepare purchase order | Purchase Officer | Purchase Manager | Procurement management |
| Receive goods | Logistics / Warehouse | Independent control where required | Logistics management |
| Process vendor bill | AP / Accountant | Chief Accountant / Financial Controller | Finance |
| Execute supplier payment | Treasury | Finance approval chain | CFO / Finance control |
| Maintain bank account | Authorized finance / payroll maintainer | Independent bank validator | Finance / Payroll governance |
| Maintain partner / product master | Authorized master-data maker | Independent master validator | Functional owner / Governance |
| Adjust inventory | Authorized stock maker | Independent approval | Logistics / Governance |
| Maintain employee data | HR Officer | HR Manager where required | HR |
| Prepare payroll | Payroll Officer | Payroll Manager / further approval | Payroll / Finance |
| Execute payroll payment | Treasury | Required independent payroll approval already completed | Finance |
| Manage project | Project Manager | BU / budget authority where required | Operations / BU |
| Review audit / violations | Compliance / Governance | Oversight | Governance |