Skip to content

Complete Studio production identity, role, audit export, and high-risk controls #32

Description

@alexeygrigorev

Parent epic: #7

Normative specs: 06 — Studio and admin API, 07 — Identity and authorization

Decision dependencies: #20, #28
Foundation dependency: #86

Outcome

Complete the Studio access-control and high-risk safety policy after the owner approves production staff identity/break-glass behavior in #20 and final high-risk controls in #28. #86 supplies the decision-free registry, authorization/session hooks, audit browser, private Studio shell, and fail-closed fixture framework.

Scope

Non-goals

Acceptance criteria

Django and integration scenarios

  1. Positive/negative matrix for every finalized role, composed roles, object policy, sensitive field, inactive staff, revoked/expired session, offboarding, and CSRF.
  2. Each approved high-risk class with fresh/stale authentication, explicit confirm/cancel, denied actor, replay, stale revision, mismatched scope/count/impact, policy outage, and the approved dual-approval state.
  3. Audit browse/export allowed and denied, bounded results, formula payloads, redaction canaries, and actor deletion (SET_NULL) retention.
  4. Production-settings checks for normal Django-admin denial and the exact approved break-glass behavior without exposing credentials.

Playwright scenarios

  1. At desktop/mobile sizes, use representative finalized roles and verify navigation/actions are present only when allowed.
  2. Exercise each distinct approved high-risk interaction, including stale-session reauthentication and cancel/deny states, without capturing credentials.
  3. Inspect audit filters/detail/export guidance and verify signed-out/revoked browser back navigation cannot expose cached data.

Dependencies

Blocked until #20 and #28 are resolved. Depends on #86. Coordinates the selected-provider implementation with #61; domain capability coverage remains owned by each domain issue and the #7 epic gate.

Delivery convention

Follow _docs/PROCESS.md. Do not begin engineering while either owner decision is open. After independent tester and PM acceptance, commit with Closes #32; no pull request.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0Must-have or release-blockingadminArea: adminauthArea: authsecurityArea: security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions