Authority follows the actor and the operation.
Map each actor to the work they can perform, with concrete role examples your engineers and security reviewers can inspect together.
Identity does not carry every permission.
The reviewed application flow verifies the cookie session with the authentication service and reads organization membership for each request. Membership must be active. Invited or revoked membership cannot authorize an operation. A role string sent by a browser is not the authority source.
The current Business roles are owner, admin, manager, cashier and viewer. They are application roles, not partner OAuth scopes. Role authority does not bypass provider capability, environment, asset or applicable plan-entitlement checks.
Selected current operation matrix
All means all authorized records within the organization; own means records created by that member. Neither permits access to another organization. This matrix documents selected operations, not every product role.
| Operation | Owner / admin | Manager | Cashier | Viewer |
|---|---|---|---|---|
| payment.view / invoice.view | All | All | Own | All |
| payment.create | Allowed | Allowed | Allowed | Denied |
| payment.collect / payment.cancel | All | All | Own | Denied |
| payment.refund | All | All | Denied | Denied |
| exception.view / export.csv | All | All | Denied | All |
| settlement.import / exception.confirm_late | All | Denied | Denied | Denied |
| staff.manage / connection.manage | All | Denied | Denied | Denied |
A corporate identity integration is separate.
This guide does not establish enterprise SSO, SCIM provisioning, partner service accounts, delegated OAuth or a corporate MFA policy for the target deployment. Agree on authentication, provisioning, offboarding, session policy and audit evidence before treating any of these as supported. Begin with named users and the narrowest approved workflow.
- Prove that a viewer cannot mutate and a cashier cannot read or collect another member’s sale.
- Prove revocation against an existing session, not only a newly signed-in user.
- Never share an owner login, privileged token or production provider credential for evaluation.