Settings Guardrails
Source-static proofRole Governance Matrix
Review-only governanceMatrixAdminOwner approval before real user provisioning or external account changesDefaultsLong-TermField: No rent ledger or resident financial rowsFollow-onOpen permissionsContinue into permission and denial-test coverage.
Roles & permissions
Default scopes and denied-by-default boundaries for every operating role.
Roles is a source-static governance surface. Admin, Manager, Owner, Field, Vendor/Cleaner, and AI Validator rows can be reviewed, but no invite, assignment, grant, mutation, or tenant activation is available.
Selected roleAdmin
Owner approval before real user provisioning or external account changes
Fixture onlyAdmin
Account/workspace configuration
Operational finance detail unless explicit finance permission is grantedMVP operator roleManagerAssigned account/workspace operations
Cross-account data, production credentials, live payment actionsSummary-onlyOwnerOwner-visible property group
Tenant ledgers, private resident payments, draft reports, non-owner payablesRestrictedFieldAssigned field work only
Financials, PII, owner statements, payables, platform payouts, rent balancesRestrictedVendor / CleanerAssigned service work only
Cleaner/vendor pay amounts, owner data, resident ledgers, guest private recordsDeferredAI ValidatorReview-only repo and synthetic fixture context
Secrets, production data, live customer records, external toolsOperating area defaultsLong-Term
Compact role preview keeps cross-role visibility readable without widening any permission surface.
Long-TermManager: Full operational rent/resident/lease contextOwner: Published owner summaries onlyField: No rent ledger or resident financial rowsAdmin: Configuration only unless finance permission is explicit
MoneyManager: Operational receivables, payouts, payables, statements, reconciliationOwner: Owner-visible statements, reports, contributions, draws, approved expensesField: Denied before rows renderAdmin: Entitlements and provider status; finance rows require permission
Work and ScheduleManager: All assigned account/workspace operationsOwner: Approved owner-impact summariesField: Assigned work, checklist, timing, evidence onlyAdmin: Role/property access configuration
Messages and AIManager: Drafts, sources, approval stateOwner: Published summaries onlyField: No private messages or AI sources unless assigned and approvedAdmin: AI access rules and integration scopes
Role Matrix
No invitationsSection 1 role-matrix carry-throughUse default scope, visible scope, denied defaults, approval gate, and status as the first arrival scan so role review stays tenant-safe and no-live.Role review remains synthetic-only, read-only, and no-invite.
| Role | Default Scope | Can See | Denied By Default | Approval Gate | Status |
|---|---|---|---|---|---|
| Admin | Account/workspace configuration | Settings, integrations, roles, permissions, entitlement placeholders | Operational finance detail unless explicit finance permission is granted | Owner approval before real user provisioning or external account changes | Fixture only |
| Manager | Assigned account/workspace operations | Properties, Schedule, Work, Messages drafts, Inspections, Money operations, Reports drafts | Cross-account data, production credentials, live payment actions | Human approval before owner-visible publication, external sends, or paid actions | MVP operator role |
| Owner | Owner-visible property group | Published owner statements, owner reports, approved expenses, contributions, draws | Tenant ledgers, private resident payments, draft reports, non-owner payables | Publication gate and owner-visible flag | Summary-only |
| Field | Assigned field work only | Assigned tasks, checklist steps, timing, evidence prompts, approved access context | Financials, PII, owner statements, payables, platform payouts, rent balances | Property assignment and task assignment | Restricted |
| Vendor / Cleaner | Assigned service work only | Assigned work order, checklist, evidence prompt, schedule window | Cleaner/vendor pay amounts, owner data, resident ledgers, guest private records | Manager assignment and evidence requirement | Restricted |
| AI Validator | Review-only repo and synthetic fixture context | Approved docs, PRs, synthetic records, review checklists | Secrets, production data, live customer records, external tools | Owner activates validator through GitHub when ready | Deferred |
Role Defaults By Operating Area
Section 2 area-defaults carry-throughRead area defaults first so cross-role visibility remains easy to scan without widening any permission surface.Operating-area defaults remain placeholders only and no-live.
| Area | Manager | Owner | Field | Admin |
|---|---|---|---|---|
| Long-Term | Full operational rent/resident/lease context | Published owner summaries only | No rent ledger or resident financial rows | Configuration only unless finance permission is explicit |
| Money | Operational receivables, payouts, payables, statements, reconciliation | Owner-visible statements, reports, contributions, draws, approved expenses | Denied before rows render | Entitlements and provider status; finance rows require permission |
| Work and Schedule | All assigned account/workspace operations | Approved owner-impact summaries | Assigned work, checklist, timing, evidence only | Role/property access configuration |
| Messages and AI | Drafts, sources, approval state | Published summaries only | No private messages or AI sources unless assigned and approved | AI access rules and integration scopes |
Role Guardrails
Roles are account-scoped, never global tenant bypassesRole assignments derive from active synthetic POC members only; denial tenant members render as zeroAdmin does not automatically bypass financial visibilityFinance visibility requires explicit permission and is not granted by role label aloneOwner role is summary-only until publication gates passField, vendor, cleaner, and inspector roles cannot see money, PII, source rows, owner statements, private messages, resident ledgers, platform payouts, or private contact dataNo auth setup, Supabase writes, database migrations, seed execution, invitations, provider setup, or real-data migrationFuture owner real data must use a separate second tenant after migration, security, and tenant-isolation approvalAI validator is review-only and requires owner activation
Route Closure
Source-static route closureRoles now carries supervisory continuity, bounded table readability, and tenant-safe role governance through this dedicated review surface.Role matrix and operating-area defaults stay synthetic-only and no-live.
Boundary rules summaryRead-only roles review only; no invite, role assignment, permission write, tenant activation, or provider execution.The receiving surface stays source-static, review-only, and ready for later no-live validation routing only.