Model EBS the way EBS works: responsibility, menu and form function, with operating-unit scope evaluated inside the rule rather than filtered afterwards.
The access model
Rules evaluate the effective permission after inheritance is resolved — then normalise it, so the same rule can reach into another platform.
In practice
Same-unit rules that fire only when both sides land in one operating unit
Custom responsibilities cloned across upgrades, resolved to real function access
Cross-unit and global-access rule scopes for unrestricted responsibilities
Book a technical demo, or start with a read-only risk assessment.