Roles and user attributes
Roles grant a user access to site or app resources, and a user's app access lists the apps their roles reach. Attributes are information about a site user, such as a department, defined by the site's attribute schema. Referenced attributes resolve selected record data into an attribute and have their own mapping lifecycle.
Roles control access; attributes describe a user. Use assign user access to change roles and user attributes to configure the schema.
An access policy evaluates caller, resource, action, and conditions; a role is one input to that decision, not the decision itself. See Access policies for how decisions are made, site roles for role lifecycle, and referenced user attributes for mapping lifecycle.