POLICY LAYER — grants authoritative

UI controls are hints only. Authorization is server-enforced via accessGrants, geography, purpose, MFA and SOD. Super Admin does not auto-receive sensitive.read. Permission-denied responses omit resource existence details.

Permission sets

Approval

Sensitive Export Set may require large-export approval under Security & Compliance.

SetModulesActionsAssigned rolesUpdated