- Sector
- Banking
- Scale
- Approximately 30,000 users supported
- Access model
- RBAC, groups and specific users applied to each item
- Working views
- Personal dashboards and permission-aware reporting
The operating problem
Broad participation could not mean broad visibility
Risk information in a bank reaches business owners, technology teams, cyber specialists, compliance teams, assurance functions and leadership. Each group needs to work with the records relevant to its responsibilities, but sensitive material cannot become visible across the organization simply because everyone uses the same platform.
The design question was therefore precise: how can thousands of people participate while permissions continue to follow each risk, control, issue and action?
How the model works
Access follows the item, while information remains connected
- Assign responsibility.A risk owner, contributor or specialist works with the item relevant to that role.
- Apply the access boundary.Roles, groups and specific-user permissions determine who can view or change the record.
- Shape the working view.Each user chooses the permitted items that matter on a personal dashboard.
- Report from the same records.Management reporting brings together information the viewer is permitted to see without recreating a separate register.
What this deployment demonstrates
Enterprise scale without seat-based access decisions
The banking deployment supports approximately 30,000 users. It demonstrates Parapet's item-level security model and the ability to support broad participation without charging a separate SaaS fee for each user.
This account does not publish the organization's identity, internal control design or confidential deployment architecture.