Skip to main content

Role hierarchy

Role definitions

The EMPLOYEE role is legacy. Employees are domain records, not platform users. The remaining self-service code path is documented technical debt scheduled for removal in Phase 11.9 and should not be granted to real accounts or built upon.

Permission groups

The mapping lives in backend/src/auth/permissions.ts. Permissions are composed from four groups:

Complete permission catalog

Catalog and organization

Employees

Entitlements

Orders

Reports

System and users

There are 33 distinct permissions covering catalog, organization, employees, entitlements, orders, reports, and system administration.

Role-permission matrix

The EMPLOYEE column reflects the legacy base permission set described above.