Ring & Knock
Operations workspaceCascade Stays — PNW
Manager preview activeManager route view selected locally. Full internal review surfaces are visible in this browser preview.
Draft work
Local work draftStage review work
Open Work

Local draft only. Nothing is dispatched or written outside this browser preview.

Permissions

Internal workspaceManager reviewDraft mode
Summary viewDecision surface first

Settings Guardrails

Source-static proof

Permission Governance Matrix

Fail-closed review
Permissions & visibility

Role visibility, denied tenants, and finance permission checks in one bounded matrix.

Permissions keeps owner summary-only, field-denied, and admin explicit-finance-permission evidence visible. The surface is read-only and cannot grant, revoke, mutate roles, invite users, or activate tenants.

Permission rows8

No checkout, payout, charge, refund, or ledger export

Permission rows8
Denied tenants0
Finance evidence rows4
Owner summary candidates1

Permission Review Metrics

Synthetic evidence only
Permission rows8
Denied tenants0
Finance evidence rows4
Owner summary candidates1

Permission Matrix

Account scoped
PermissionManagerOwnerFieldAdminGuardrail
account.manageNoNoNoYesNo external account changes or invitations yet
property.readAssigned accountOwner-visible assignedAssigned work onlyConfiguration contextAll reads require account_id and property assignment
work.manageYesNoAssigned checklist onlyNo by defaultNo live dispatch or external messages
money.view_operationalYesSummary-onlyNoExplicit finance permission onlyProvider-agnostic rows only; no live payments
resident.ledger.readYesNoNoExplicit finance permission onlyPrivate resident ledger rows never render to Owner or Field
owner.statement.publishApproval onlyRead publishedNoNo by defaultNo email, export, or external sharing
integrations.manageNoNoNoPlaceholder onlyNo tokens, webhooks, credentials, or external writes
ai.reviewDraft reviewNoNoScope configurationAI cannot send, publish, charge, pay, or release access

Visibility Rules

AreaManagerOwnerFieldAdminSafety BoundaryNext Action
Property and work reviewAssigned account reviewPublished owner-visible context onlyAssigned work and checklist onlyConfiguration boundary onlyNo dispatch, invite, or tenant-bypass actionKeep route review read-only
Money and ledger reviewOperational readSummary-onlyDeniedExplicit finance permission onlyNo checkout, payout, charge, refund, or ledger exportConfirm finance scope before any future provider work
Owner publication and reportsApproval reviewPublished artifacts onlyDeniedNo by defaultNo publish, send, export, or external sharingRequire owner-visible flags and publication gate
Platform and integration governanceDeniedDeniedDeniedPlaceholder-only reviewNo tokens, secrets, credentials, or external writesKeep provider setup deferred

Permission Test Cases

ScenarioExpectedEvidenceNext Action
Field opens MoneyZero financial rows renderRole-filtered financial views deny 4 active POC money rows to Field and exclude denial tenantsKeep denial test before database migrations, Supabase writes, or real-data migration
Owner opens Long-Term delinquencyOwner-visible summary only, no resident ledger rowsOwner summary-only publication gate over 1 active POC report rowsRequire approved report/statement source and owner-visible flags
Admin opens billingEntitlements visible, Stripe/payment setup remains deferredAdmin configuration view does not grant operational finance rows without explicit finance permissionOwner decides future payment provider later; no provider setup in Gate A
AI validator reads project contextRepo/synthetic fixture review onlyIntegration and role guardrails stay account-scoped to the synthetic POC tenantActivate through GitHub review only when owner is ready
Denial tenant report requestedNo rows render from denial tenant accountsPermissions route evidence carries denialTenantCount 0 and active POC account onlyKeep cross-account denial before any real-data import
Future owner real-data migration requestedBlocked until separate second tenant is approvedAccount Settings tenant gate requires migration, security, and tenant-isolation approvalDo not mix owner real data into the synthetic POC tenant

Audit Queue

EventStatusEvidenceTenant SafetyNext Action
Field finance denial reviewPasses fail-closed reviewField cannot see 4 finance evidence rowsPOC account only; denial tenants excludedKeep denial case in synthetic regression coverage
Owner summary visibility checkPublication-gated1 owner-summary candidates remain boundedOwner never receives resident ledger detailRequire published and owner-visible state before release
Admin finance scope reviewExplicit permission required4 scoped role rows remain account-boundNo global tenant bypass or hidden ledger backdoorPreserve explicit-finance-permission requirement

Permission Guardrails

Permission checks must run after account membership and before rows renderClient-provided account ids are hints onlyRoles are scoped to the active synthetic POC account and never grant global tenant bypassDenial tenant records are excluded from permission-route evidenceFinancial access requires role plus explicit permission where applicableAdmin financial rows require explicit finance permission and never bypass tenant isolationOwner visibility depends on publication state and owner-visible flagsField, cleaner, vendor, and inspector roles cannot see financial report rows, owner statements, source rows, private messages, resident ledgers, platform payouts, or private contact dataNo auth setup, Supabase writes, database migrations, seed execution, invitations, provider setup, or real-data migrationFuture owner real data must use a separate second tenant after migration, security, and tenant-isolation approvalEvery denied case should be auditable without exposing hidden row contents

Route Closure