Access Control
Governance-first role visibility, client-local control policy, and theme guardrails for managed engines.
Live Governance Context
Current governance, platform, runtime, and integration posture behind access decisions.
Theme Registry
Approved presentation-only theme packages that can be assigned to client-local engine panels.
Commerce
Presentation onlyApprovedSafe for client-local storefront administration.Neutral operations
Presentation onlyApprovedSuitable for admin-heavy storefronts with no custom script support.Tenant branded
CSS and image assets onlyReview requiredRequires validation before client assignment.ACL Matrix
Role and privilege posture that governs platform operators and client-local admin personas.
| Role | Scope | Privileges | Session Policy | Approval Path |
|---|---|---|---|---|
| Governance Operator | Platform-wide | Approve provisioning, privileged access, lease exceptions | MFA + reason logging | Self-service for standard approvals |
| Client Admin Operator | Per engine local control panel | Manage approved engine-local settings, review branded themes, request support escalation | Delegated engine-local access only | Escalates to Governance Operator |
| Finance Reviewer | Commercial controls | Approve billing exceptions, validate lease cost exposure | Read-mostly with approval write access | Shared approval with Governance Operator |
| Support Auditor | Audit visibility | Review access history, read privileged action trails | Read-only governed sessions | No direct mutation rights |
Client Control Policies
Engine-local control surfaces that may be provisioned for Client Admin Operators.
- 01Storefront client adminSaaS storefront -> Catalog, orders, branding, and user-local settingsNative or approved custom presentation package · No governance, node, or deployment controls are exposed.
- 02BaaS read-only client adminBaaS -> Status visibility, approved settings, and audit-safe controlsNo client theming by default · Production integration settings remain governance controlled.
Local ACL Workflow
Approve or deny the local ACL request queue while staying anchored to the live governance posture.
Needs governed admin access for launch review
Northwind StudioRequested by: OwnerRisk: MediumStatus: Pending approvalBilling exception review for overage reconciliation
POD Engine CharlieRequested by: Governance Operator 2Risk: LowStatus: Needs justificationEscalation required for Governance Operator.Audit visibility during provisioning handoff
Harbor Goods PODRequested by: Support LeadRisk: LowStatus: Pre-clearedEscalation required for Governance Operator.Theme Guardrails
Theme packages stay limited to presentation-only scope even when local client control is enabled.
- 01Custom themes stop at CSS and imagesClient Admin Operators can only apply approved presentation assets and template styling.No backend logic, scripts, or policy mutation is allowed.
- 02Governance owns deployment and placementClient-local access never grants Production Node, AI service, or API package control.Those controls remain on the Governance Node.
- 03Audit continuity stays intactTheme selection and local access posture changes must remain visible in the audit trail.This keeps presentation changes reviewable.
Role-Aware Actions
Governed operational actions stay explicit about role requirements while client-local control remains bounded.
Open a governed admin session for a tenant when launch-blocking work requires intervention.
Required Role: Governance OperatorCurrent Session: Governance OperatorAvailable nowRaise a burst capacity exception before provisioning final approval.
Required Role: Governance Operator + Finance ReviewerCurrent Session: Governance OperatorAvailable nowIncrease Worker AI cycle cap outside the default lease envelope.
Required Role: Governance OperatorCurrent Session: Governance OperatorAvailable nowAuthorize a governed rollback to the last certified deployment package when release health regresses.
Required Role: Governance Operator + Support AuditorCurrent Session: Governance OperatorAvailable nowRetire an engine with explicit revocation of AI leases, API services, and client control access.
Required Role: Governance Operator + Finance ReviewerCurrent Session: Governance OperatorAvailable nowLive Access Audit
Recent access-control audit events from the live governance snapshot when available.
- 01ACL seed package approved for Harbor GoodsSupport Auditor visibility was pre-cleared for provisioning handoff.Category: access-control / Severity: low