Roles & access
Define least-privilege roles, grant them to subjects within a merchant scope, and review every privileged-access decision.Your accesspreprod-root-aa5d7d37b2444199efcf718b7073e2e0
super_admin
38 permissions · all merchantsAssignments (6)
| Subject | Role | Merchant scope | Granted by | Granted | Expires | |
|---|---|---|---|---|---|---|
| preprod-root-aa5d7d37b2444199efcf718b7073e2e0 | Super Admin (super_admin) | All merchants | preprod-rotation-2026-09-08 | 9/8/2026, 10:39:28 PM | Never | |
| dev-admin-0001 | Read Only (read_only) | All merchants | preprod-bootstrap | 9/1/2026, 1:54:18 AM | Never | |
| Larry@CelticOakCapital.com | Super Admin (super_admin) | All merchants | bryant@si3.io | 8/25/2026, 1:18:02 AM | Never | |
| Ken@CelticOakCapital.com | Super Admin (super_admin) | All merchants | bryant@si3.io | 8/25/2026, 1:18:02 AM | Never | |
| scoped-tester | Merchant Support (merchant_support) | m-alpha | bryant@si3.io | 8/25/2026, 12:37:01 AM | Never | |
| bryant@si3.io | Super Admin (super_admin) | All merchants | bryant@si3.io | 8/25/2026, 12:36:44 AM | Never |
How this step works
SIPOCSuppliersWhere the work comes from
Marketplace services· outside the apps
InputsWhat this step needs to do its job
- The catalogue of permissions the system defines
- Existing roles and who holds them
- Least-privilege rules
ProcessWhat happens here, in order
- Define roles as named sets of permissions
- Assign and remove people from roles
- Record every privileged change in an audit trail
OutputsWhat this step produces
- Roles and assignments that gate every other admin screen
- A privileged-access audit record
CustomersWho uses that output next