Skip to content

Account – Settings – Roles

  • Path: /account/settings/roles (TBD)
  • Parent: settings.md

Define and manage role bundles used across the org/workspaces.

  • Org Admin
  • Permissions: roles.manage (TBD)

Reference: Roles & Permissions Model

  • Role list
  • Role detail editor (permissions matrix)

TBD

  • Empty: no custom roles
  • Loading: fetch roles
  • Error: unauthorized / validation errors
  • Complete: roles managed
  • Roles map to permissions; changes require audit.

Domain refs: Roles & Permissions Model

  • GET /roles
  • POST /roles
  • PUT /roles/{id}
  • Role changes have org-wide blast radius; enforce least-privilege workflows and approvals (TBD).
  • Prevent privilege escalation and ensure changes are auditable and attributable.
  • Role is in use by users/workspaces; deletion/disable behavior is TBD.
  • Concurrent edits to the same role; conflict resolution is TBD.
  • Prevent privilege escalation; audit role edits

Reference: Security & Compliance

TBD

Reference: Analytics Events (MVP)