Assignments vs permissions
Permissions answer what a person is allowed to do. Assignments answer why that person is responsible for a specific record.
Keeping them separate makes access easier to explain. A supervisor may have permission to manage many records, while an assignee is connected to one record because the work is currently theirs. Both facts matter, but they mean different things.
Entity Security Statements can use both facts in one decision. A Permission
Assignment links an action such as View or Update to a Statement; a responsibility assignment
provides a record-specific fact such as Assignee or Reviewer. Assignment Rules
separately decide who may Add, Replace, or Close assignments. Having
Update does not grant assignment authority, and being assigned does not grant
an action unless a Security Statement assigned to that Permission matches.
Assignments may target users or Responsibility Groups. Their cardinality, eligibility, required behavior, and history are defined by the current Responsibility Definition, not by an Entity relation or inherited access mode.