Who may see and manage what — and what someone in that function must know and be able to do. The role is where assignment and authority meet.
A role in Oanax does two things at once. It sets permissions: who can see and manage what, down to department level. And it describes the function: which must-reads, modules and certificates belong to this work.
That makes the role the point where everything meets: give someone the role, and the requirements come with it. The system also sees who should have something based on their role and does not yet.
You manage roles yourself, and a person can hold more than one — like in real work.