Apply workspace, portfolio and program scope on every query and action.
Roles and permissions
Separate proposal preparation, gate review, funding approval and executive visibility.
How permissions work
5 rulesPreserve field masking for estimated costs, benefits and reviewer scores.
Require distinct Portfolio Manager and Finance funding decisions; preparers cannot approve themselves.
Admin configures the system and cannot rewrite closed decisions.
Use authenticated Users bindings and an append-only platform audit trail.
The roles
The PMO Lead — owns the function. Curates Portfolios, organizes Programs, owns the Backlog ranking, runs the quarterly PortfolioReviews, facilitates GateReviews, and owns the rebalance decisions.
Owns one Program (and any nested sub-Programs) — the Initiatives within it, the cross-Initiative Dependencies, the rolled-up Program KPIs.
Owns one Initiative end-to-end — authors the Proposal, prepares gate packets, owns the KPIs catalog for the Initiative, requests funding, raises Risks and Dependencies, and reports KPIs (or delegates to the named ProjectManager).
A reviewer-only role layered on the user — when assigned to a GateScorecards row (via the stage-gate-promotion workflow), gains read access to the gate packet and write access to own GateScorecards rows.
Read-only on Portfolio context for own Projects (so a delivering PM can see how their Project fits the Initiative narrative) and write on KPIMeasurements they are named owner of.
Read-only dashboard view — the CEO / COO / business unit GM who consumes the portfolio output without operating the system.
Read-only on Portfolio context with write on Budgets and co-approver on FundingAllocations. The reconciliation seat between Portfolio plan and the GL.