Skip to content

History / Module Access Control

Revisions

  • Add Module Access developer guide (wiring new modules/pages/endpoints into Phase 3 enforcement); link from page + sidebar

    @edmozley edmozley committed Jul 11, 2026
  • Module Access Control: document the in-place Access-level toggle; fix team default (0) + drop unbuilt save-time warning claim

    @edmozley edmozley committed Jul 11, 2026
  • Module Access Control: mark phases 2 & 3 shipped; document read-gating follow-up

    @edmozley edmozley committed Jul 11, 2026
  • Module Access Control: add implementation-phases status table

    @edmozley edmozley committed Jul 11, 2026
  • Module Access Control: correct team default (0, not all) Teams default to granting NO modules (matching team company-access), not all-access — under the default 'most' union mode a team defaulting to all would silently hand every member every module. Clarified the strict-mode lock-out case and the safe-upgrade wording accordingly.

    @edmozley edmozley committed Jul 11, 2026
  • Add Module Access Control page (issue #30) Documents the team-based module access design: mirrors company access (individual + team grants + all-modules flag, one choke-point resolver), the most/least-permissive policy with the strict-mode foot-gun called out, server-side per-module enforcement, the summary/edit UI, the effective-access tool, and the safe-upgrade grandfather. Linked under Security.

    @edmozley edmozley committed Jul 11, 2026