POLICY LAYER — grants authoritative

UI controls are hints only. Authorization is server-enforced via accessGrants, geography, purpose, MFA and SOD. Super Admin does not auto-receive sensitive.read. Permission-denied responses omit resource existence details.

Roles

RoleDescriptionDefault modulesAdminsSystem