Role hierarchy
Role definitions
The EMPLOYEE role is legacy. Employees are domain records, not platform users. The remaining self-service code path is documented technical debt scheduled for removal in Phase 11.9 and should not be granted to real accounts or built upon.
Permission groups
The mapping lives inbackend/src/auth/permissions.ts. Permissions are composed from four groups:
Complete permission catalog
Catalog and organization
Employees
Entitlements
Orders
Reports
System and users
There are 33 distinct permissions covering catalog, organization, employees, entitlements, orders, reports, and system administration.
Role-permission matrix
The EMPLOYEE column reflects the legacy base permission set described above.