What's the difference between groups and roles?
A lot of identity management implementations use roles in addition to groups. How are they different? So far I haven't found a compelling use case for separating the two. All the explanations I've read are vague and hand-wavey. Can you give a good example where having roles and groups are necessary? Person - Group - Roles A person is a member of one or more groups. A group is assigned multiple roles. Example: Two roles exist in a system stock_purchaser , timecard_supervisor . Two groups exist in a system shift_supervisor , regional_manager . regional_manager has the stock_purchaser and