01
Model
- RBAC with org/tenant scoping and row-level constraints.
- Approvals for sensitive actions (overrides, refunds, schedule changes).
- Reason codes required for exceptions.
Platform / Permissions
Least-privilege by design with approvals, reason codes, and full change history.
01
02
Audit logs for roles, assignments, billing state, and proof edits.
Visibility controls for customer-facing updates and notifications.
Scoped support roles with recorded actions and temporary elevation when approved.