A role is a named bundle of permissions, and a permission is scoped to one specific area of the product rather than to the application as a whole. These are the sixteen:
A seventeenth marker, none, exists alongside them: setting a role's permission for an area to none switches that area off for anyone holding only that role, rather than defaulting to some minimal read access. Splitting requests from management, and the competency matrix from competency management, is deliberate: it lets an organisation grant someone the authority to approve a leave request without also granting them the authority to redefine the leave policy, or to see the whole organisation's qualification matrix without being able to edit a single qualification in it.
Within several of these areas the model goes one level finer still: leave requests, for example, separates create, delete, send-reminder and cancel into independent actions, and baseline (work, off, swap) requests separates approve and decline from the act of creating one. An organisation can grant a team manager the authority to approve a swap without granting them the authority to delete a leave request.