ADORSYS-GIS / ADORSYS-GIS/lightbridge-authz
[Story]: Expanded role model (org-admin, team-admin, auditor, end-user)
- Ngôn ngữ chính
- Rust
- Star
- 0
- Fork
- 1
- Merge trung bình
- 6 giờ 42 phút
- Pull request đã merge (30 ngày)
- 246
Mô tả
## Summary
Define the expanded role model — org-admin, team-admin, auditor, end-user — and their permission boundaries.
## Intent / Source of truth
This is the foundational definition the rest of the epic's enforcement work builds on. Part of [Epic] RBAC beyond admin and user.
## Scope
- [ ] Role and permission-boundary definitions for all four roles
- [ ] Mapping of existing platform actions to the roles allowed to perform them
- [ ] Role-assignment API (who can grant which role to whom)
## Out of scope
- Enforcement implementation (separate story) — this story is the model/definition
## Verification
A reviewed permission matrix (role x action) exists and is used as the source of truth for the enforcement story's test suite.
## Risk assessment
A definition-only story creates exactly the #177 risk if not immediately followed by enforcement tests — track this story and a4s2 as a pair, not sequential-and-forgettable.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.