You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Decision dependencies: #20, #28
Foundation dependency: #86
Outcome
Complete the Studio access-control and high-risk safety policy after the owner approves production staff identity/break-glass behavior in #20 and final high-risk controls in #28. #86 supplies the decision-free registry, authorization/session hooks, audit browser, private Studio shell, and fail-closed fixture framework.
Finalize the effective recommended-role matrix, role administration, and required function/object/sensitive-field policies for the foundation and then-registered management capabilities. Domain issues continue to own registration of their domain actions.
Turn the Decision: Confirm high-risk action approvals and reauthentication #28 decision into the final high-risk action catalog and policy: scope/count/impact presentation, approved authentication-freshness rule and API equivalent, explicit confirmation, replay/stale-revision behavior, and any approved dual-approval rule/review trigger.
Every management capability available when this issue is implemented has an explicit effective role plus function/object/field policy; no is_staff, group-name, or superuser-only authorization shortcut bypasses Add the decision-free Studio authorization and audit foundation #86 hooks.
Role grants and every action classified high risk by approved Decision: Confirm high-risk action approvals and reauthentication #28 show exact scope/count/impact and enforce the approved fresh-authentication, explicit-confirmation, concurrency, idempotency, audit, cancellation, and denied-action behavior in Studio and through the API-equivalent policy hook.
The approved dual-approval choice (implemented or explicitly deferred with its review trigger) is encoded and tested; unresolved or unknown high-risk policy remains fail closed.
Audit export is separately permissioned, bounded, formula-neutralized, and redacted; the browser/export never exposes credentials, tokens, bodies, management links, or unnecessary PII.
Studio and the approved production Django-admin/break-glass surface are private/no-store/noindex; ordinary Django admin is unavailable in production unless Decision: Select the staff OIDC provider and break-glass policy #20 explicitly approves a separately protected path.
Django and integration scenarios
Positive/negative matrix for every finalized role, composed roles, object policy, sensitive field, inactive staff, revoked/expired session, offboarding, and CSRF.
Each approved high-risk class with fresh/stale authentication, explicit confirm/cancel, denied actor, replay, stale revision, mismatched scope/count/impact, policy outage, and the approved dual-approval state.
Audit browse/export allowed and denied, bounded results, formula payloads, redaction canaries, and actor deletion (SET_NULL) retention.
Production-settings checks for normal Django-admin denial and the exact approved break-glass behavior without exposing credentials.
Playwright scenarios
At desktop/mobile sizes, use representative finalized roles and verify navigation/actions are present only when allowed.
Exercise each distinct approved high-risk interaction, including stale-session reauthentication and cancel/deny states, without capturing credentials.
Inspect audit filters/detail/export guidance and verify signed-out/revoked browser back navigation cannot expose cached data.
Dependencies
Blocked until #20 and #28 are resolved. Depends on #86. Coordinates the selected-provider implementation with #61; domain capability coverage remains owned by each domain issue and the #7 epic gate.
Delivery convention
Follow _docs/PROCESS.md. Do not begin engineering while either owner decision is open. After independent tester and PM acceptance, commit with Closes #32; no pull request.
Parent epic: #7
Normative specs: 06 — Studio and admin API, 07 — Identity and authorization
Decision dependencies: #20, #28
Foundation dependency: #86
Outcome
Complete the Studio access-control and high-risk safety policy after the owner approves production staff identity/break-glass behavior in #20 and final high-risk controls in #28. #86 supplies the decision-free registry, authorization/session hooks, audit browser, private Studio shell, and fail-closed fixture framework.
Scope
Non-goals
Acceptance criteria
is_staff, group-name, or superuser-only authorization shortcut bypasses Add the decision-free Studio authorization and audit foundation #86 hooks.Django and integration scenarios
SET_NULL) retention.Playwright scenarios
Dependencies
Blocked until #20 and #28 are resolved. Depends on #86. Coordinates the selected-provider implementation with #61; domain capability coverage remains owned by each domain issue and the #7 epic gate.
Delivery convention
Follow
_docs/PROCESS.md. Do not begin engineering while either owner decision is open. After independent tester and PM acceptance, commit withCloses #32; no pull request.