BlackOakAdmin

Roles & access

Define least-privilege roles, grant them to subjects within a merchant scope, and review every privileged-access decision.
Your accesspreprod-root-aa5d7d37b2444199efcf718b7073e2e0
super_admin
38 permissions · all merchants
PeopleRolesAccess audit
Roles (7)
Compliance Reviewer compliance_reviewer Built-in · 13 permissions
Compliance oversight: product approval, restrictions, review moderation, audit.
catalog
catalog:approvecatalog:readcatalog:recall
compliance
compliance:readcompliance:review
merchant
merchant:read
notification
notification:read
reports
reports:read
reviews
reviews:moderatereviews:read
service
service:approveservice:read
taxonomy
taxonomy:read
Content Admin content_admin Built-in · 7 permissions
Public content, disclosures, taxonomy, and merchandising curation.
catalog
catalog:read
content
content:publishcontent:read
merchandising
merchandising:curatemerchandising:read
taxonomy
taxonomy:readtaxonomy:write
Finance/Refund Admin finance_admin Built-in · 7 permissions
Commission configuration and refund authority.
commission
commission:readcommission:write
orders
orders:read
refund
refund:issue
reports
reports:read
returns
returns:decidereturns:read
Merchant Support merchant_support Built-in · 10 permissions
Supports merchants: activation review and merchant-facing order/return context.
catalog
catalog:read
feedback
feedback:readfeedback:write
merchant
merchant:readmerchant:review
notification
notification:read
orders
orders:read
reports
reports:read
returns
returns:read
service
service:read
Operations Admin operations_admin Built-in · 24 permissions
Day-to-day marketplace operations: catalog approvals, orders, returns, merchandising.
cases
cases:decidecases:read
catalog
catalog:approvecatalog:readcatalog:recall
feedback
feedback:readfeedback:write
inventory
inventory:read
merchandising
merchandising:curatemerchandising:read
merchant
merchant:read
notification
notification:read
ops
ops:readops:replay
orders
orders:annotateorders:read
reports
reports:read
returns
returns:decidereturns:read
reviews
reviews:read
roles
roles:read
service
service:approveservice:read
taxonomy
taxonomy:read
Read Only read_only Built-in · 19 permissions
View-only access across the administrative surfaces. Holds no write permission.
cases
cases:read
catalog
catalog:read
commission
commission:read
compliance
compliance:read
config
config:read
content
content:read
feedback
feedback:read
inventory
inventory:read
merchandising
merchandising:read
merchant
merchant:read
notification
notification:read
ops
ops:read
orders
orders:read
reports
reports:read
returns
returns:read
reviews
reviews:read
roles
roles:read
service
service:read
taxonomy
taxonomy:read
Super Admin super_admin Built-in · 38 permissions
Full administrative access, including granting and revoking roles.
cases
cases:decidecases:read
catalog
catalog:approvecatalog:readcatalog:recall
commission
commission:readcommission:write
compliance
compliance:readcompliance:review
config
config:readconfig:write
content
content:publishcontent:read
feedback
feedback:readfeedback:write
inventory
inventory:read
merchandising
merchandising:curatemerchandising:read
merchant
merchant:readmerchant:reviewmerchant:suspend
notification
notification:read
ops
ops:readops:replay
orders
orders:annotateorders:read
refund
refund:issue
reports
reports:read
returns
returns:decidereturns:read
reviews
reviews:moderatereviews:read
roles
roles:assignroles:read
service
service:approveservice:read
taxonomy
taxonomy:readtaxonomy:write
Edit role — Content AdminCancel edit
Do not enter
No medical or sensitive personal informationThe role name and description is free text and is stored by the Marketplace — reasons are often shown to the merchant or the shopper they concern. Do not enter health conditions, symptoms, diagnoses, medications, treatment history, or anyone’s sensitive personal details — not a shopper’s, not a merchant’s, and not a practitioner’s. Keep it to what the decision needs.
PermissionsGrant only what the role needs — roles:assign grants the ability to grant everything else.
cases
catalog
commission
compliance
config
content
feedback
inventory
merchandising
merchant
notification
ops
orders
refund
reports
returns
reviews
roles
service
taxonomy

How this step works

SIPOC
Who supplies this step, what it needs, what it does, what it produces, and who uses the result. Suppliers and customers are links — follow them to walk the workflow, including into the consumer and merchant apps.
SuppliersWhere the work comes from
InputsWhat this step needs to do its job
  • The catalogue of permissions the system defines
  • Existing roles and who holds them
  • Least-privilege rules
ProcessWhat happens here, in order
  1. Define roles as named sets of permissions
  2. Assign and remove people from roles
  3. Record every privileged change in an audit trail
OutputsWhat this step produces
  • Roles and assignments that gate every other admin screen
  • A privileged-access audit record
How this step works