Roles & Access
Roles and permissions: what a person may see and do, scoped to the company they work in.
Roles & Access is how Remven stays default-deny. Permissions are declared by each app (`module.resource.action`), then granted through roles on a company or the organization. A person is not “an admin” in the abstract; they hold a role in a place.
What you can do
- 01
Permissions in code, roles in the workspace
Each module names what can be done. You assemble roles from those names; you do not invent a back door.
- 02
Scoped to where they work
A role on one company does not open another. Group structures stay honest.
- 03
The people list is not the password list
Inviting someone and giving them a role are deliberate acts, audited like any other privileged change.