About Work Praise Resume Contact
নিয়ন্ত্রণ
doselect (Naukri ecosystem) // Role Based Access Control

doselect access management system.

প্রবেশাধিকার ব্যবস্থাপনা Access Management

From "Everyone is an Admin" to Enterprise-Ready Control

Role

Lead UX Designer

Company

Naukri.com / Doselect

Scope

RBAC · Enterprise SaaS

Scale

3,000+ organisations

সমস্যা

the problem.

সমস্যাthe problem

"When Everyone Has Power, No One Has Control"

DoSelect serves 3,000+ organizations with rapidly scaling teams and increasingly complex internal structures. But beneath the surface, a critical flaw existed:

Every user inside a company account had the same access level.

This meant admins couldn't delegate responsibilities without risking overexposure, data leaks, or accidental misuse. As organizations grew — adding recruiters, hiring managers, L&D teams, and ops users — the lack of access control became more than a usability issue. It became a security liability.

Across products like Assessments, Interviews, Contests, and Speech Sense, the platform couldn't reliably answer a basic enterprise question:

"Who can see what — and who can do what?"

why this mattered, beyond UX.

ব্যবসায়িক প্রভাবbusiness impact

From a business standpoint, the impact was immediate and measurable.

  • "Everyone is an admin" failed security reviews for mid-to-large enterprises
  • RBAC became a hard blocker for upsells and renewals
  • Enterprise buyers expected role-based control as table stakes, not a feature request

"This wasn't about adding permissions. This was about unlocking enterprise adoption."

গবেষণা

research & discovery: looking beyond roles and permissions.

অনুসন্ধানdiscovery

grounded in real signals, not assumptions.

Inputs used:

  • Internal product usage data
  • Conversations with recruiters and company admins
  • Support tickets related to access confusion and errors

key insights that shaped the system.

What started as a permissions problem quickly revealed adjacent design opportunities.

  • Not all users are equal — but the product treated them as such
  • Admins think in roles, not individual permissions
  • Over-granular controls increase confusion and setup time
  • Backward compatibility was non-negotiable
  • Most companies don't need team-level controls on day one
  • Role creation and user invitation must stay simple — even with complex products

"The insight was clear: power needs structure, not complexity."

design approach: enterprise-grade MVP.

We designed an RBAC (Role-Based Access Control) system that balanced security, usability, and scale.

Core principles:

  • Least privilege by default — no one gets more access than needed
  • Standardized privilege groups across products
  • Auditable user actions through activity logs
  • Backward-compatible with existing customers
  • Future-ready for teams and geo-based controls — without shipping that complexity in MVP

"Design for tomorrow, ship for today!"

কাঠামো

system design: how RBAC was structured.

RBAC was modeled around how DoSelect is already purchased and used, not theoretical org charts. Core entities:

Company AccountUnique organization inside DoSelect
ProductPurchased modules — Assessments, Interviews, Contests, Speech Sense
UserIndividual account within a company
PrivilegeGranular action — e.g. Create Assessment, View Reports
Privilege GroupLogical buckets of privileges — e.g. Reporting Management
Access LevelNo View / View Only / Edit

"Pages remain visible. Actions are disabled. Tooltips explain why. Restriction without confusion."

key user flows.

role creation & management.

  • Admin creates a role
  • Selects company-enabled products
  • Assigns privilege groups with access levels
  • Changes propagate automatically to all users in that role

user invitation & lifecycle.

  • Admin invites users and assigns roles
  • Users remain pending until onboarding
  • Invitations can be resent or revoked
  • Users can be activated or deactivated without data loss

backward compatibility: zero disruption, full control.

Rolling out RBAC to thousands of active customers required precision. We ensured:

  • Existing users retained maximum access by default
  • Inactive users stayed inactive
  • No workflows broke post-launch
  • New users required explicit role assignment

"We paired the rollout with clear email communication to guide adoption without friction."

প্রভাব

measuring success: adoption, not just enablement.

30%
of active companies adopted RBAC
80+
companies created 4+ custom roles

To measure real-world impact, we focused on behavioral adoption, not just feature enablement. During the MVP phase, 30% of active companies adopted RBAC workflows — actively assigning roles, restricting access, and managing users with intent. More importantly, 80+ companies created four or more custom roles, signaling trust in the system and confidence in modeling their internal structures within DoSelect.

This shift validated strong product–market fit with low setup friction — and marked a turning point for the platform. RBAC moved DoSelect away from an "all-users-are-admins" model to a secure, scalable, enterprise-ready system, enabling teams to grow without increasing risk. Admins gained clarity and control, while the platform unlocked a foundation for future capabilities such as team-based access, attributes, and data scoping.

"RBAC didn't just add control — it unlocked growth."