BlackOakAdmin

Roles & access

Define least-privilege roles, grant them to subjects within a merchant scope, and review every privileged-access decision.
Your accesspreprod-root-aa5d7d37b2444199efcf718b7073e2e0
super_admin
38 permissions · all merchants
PeopleRolesAccess audit
Do not enter medical or sensitive personal information. Search and filter terms is stored by the Marketplace and is not a medical channel.
Assignments (6)
SubjectRoleMerchant scopeGranted byGrantedExpires
preprod-root-aa5d7d37b2444199efcf718b7073e2e0Super Admin (super_admin)All merchantspreprod-rotation-2026-09-089/8/2026, 10:39:28 PMNever
dev-admin-0001Read Only (read_only)All merchantspreprod-bootstrap9/1/2026, 1:54:18 AMNever
Larry@CelticOakCapital.comSuper Admin (super_admin)All merchantsbryant@si3.io8/25/2026, 1:18:02 AMNever
Ken@CelticOakCapital.comSuper Admin (super_admin)All merchantsbryant@si3.io8/25/2026, 1:18:02 AMNever
scoped-testerMerchant Support (merchant_support)m-alphabryant@si3.io8/25/2026, 12:37:01 AMNever
bryant@si3.ioSuper Admin (super_admin)All merchantsbryant@si3.io8/25/2026, 12:36:44 AMNever
Grant a roleGranting a role a subject already holds re-scopes that grant rather than adding a second one.
Do not enter
No medical or sensitive personal informationThe subject reference and merchant scope is free text and is stored by the Marketplace — reasons are often shown to the merchant or the shopper they concern. Do not enter health conditions, symptoms, diagnoses, medications, treatment history, or anyone’s sensitive personal details — not a shopper’s, not a merchant’s, and not a practitioner’s. Keep it to what the decision needs.

How this step works

SIPOC
Who supplies this step, what it needs, what it does, what it produces, and who uses the result. Suppliers and customers are links — follow them to walk the workflow, including into the consumer and merchant apps.
SuppliersWhere the work comes from
InputsWhat this step needs to do its job
  • The catalogue of permissions the system defines
  • Existing roles and who holds them
  • Least-privilege rules
ProcessWhat happens here, in order
  1. Define roles as named sets of permissions
  2. Assign and remove people from roles
  3. Record every privileged change in an audit trail
OutputsWhat this step produces
  • Roles and assignments that gate every other admin screen
  • A privileged-access audit record
How this step works