ADORSYS-GIS / ADORSYS-GIS/lightbridge-authz

[Story]: Expanded role model (org-admin, team-admin, auditor, end-user)

Đang mở
#263 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
user-story
Ngôn ngữ chính
Rust
Star
0
Fork
1
Merge trung bình
6 giờ 42 phút
Pull request đã merge (30 ngày)
246

Mô tả

## Summary
Define the expanded role model — org-admin, team-admin, auditor, end-user — and their permission boundaries.

## Intent / Source of truth
This is the foundational definition the rest of the epic's enforcement work builds on. Part of [Epic] RBAC beyond admin and user.

## Scope
- [ ] Role and permission-boundary definitions for all four roles
- [ ] Mapping of existing platform actions to the roles allowed to perform them
- [ ] Role-assignment API (who can grant which role to whom)

## Out of scope
- Enforcement implementation (separate story) — this story is the model/definition

## Verification
A reviewed permission matrix (role x action) exists and is used as the source of truth for the enforcement story's test suite.

## Risk assessment
A definition-only story creates exactly the #177 risk if not immediately followed by enforcement tests — track this story and a4s2 as a pair, not sequential-and-forgettable.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.