docs: integrate account authorization model
This commit is contained in:
1 parent
191c1a1aad
commit
ffda0d5f3f
6 files changed
+108
-6
No files matched your search
@@ -0,0 +1,46 @@
|
||||
# AUTH-001: Fixed-scope account authorization
|
||||
|
||||
## Status
|
||||
|
||||
Accepted
|
||||
|
||||
## Date
|
||||
|
||||
2026-09-01
|
||||
|
||||
## Context
|
||||
|
||||
The platform already required login but treated the fixed deployment scope as a shared administrator workspace. It needed administrator-maintained accounts, per-user task isolation, a team-lead oversight role, creator/original-input audit, and explicit task-type eligibility without introducing tenant or organization administration.
|
||||
|
||||
## Decision
|
||||
|
||||
- Keep one internal `organization_id` deployment scope and do not expose organization selection or tenant administration.
|
||||
- Use three roles: `admin`, `team_lead`, and `user`.
|
||||
- Administrators manage account lifecycle, passwords, sessions, global settings/audit, AgentBus/system tasks, and all manual tasks. They always hold all 18 registered manual business routes.
|
||||
- Team leads and ordinary users use normal business APIs only for their own manual tasks. New non-administrator accounts start with no task-type grants and may invoke only routes explicitly granted by an administrator.
|
||||
- Re-read route authorization before intake and relevant task state transitions. Known denied routes and unknown/non-unique routes fail closed before parsing, plugin dispatch, or ERP execution.
|
||||
- Give team leads a dedicated read-only operations dashboard over all manual account tasks. It exposes who acted, the business instruction, and the readable business result, but not parser/executor payloads or mutation authority.
|
||||
- Preserve creator and input-turn attribution with encrypted input at rest. Routine removal is archive/restore; irreversible purge is not exposed.
|
||||
- Keep AgentBus authorization as a separate administrator-controlled channel boundary.
|
||||
|
||||
## Rationale
|
||||
|
||||
This model fits a single-organization deployment while enforcing least privilege, owner isolation, business-facing oversight, and auditable denial without weakening the existing ERP confirmation and write-safety gates.
|
||||
|
||||
## Consequences
|
||||
|
||||
- Migrations 015–017 must be applied before the updated control plane starts.
|
||||
- Existing accounts migrate as administrators; newly created team leads and users require explicit task grants.
|
||||
- Permission revocation can block an existing task at confirmation or browser claim even when an administrator attempts the transition.
|
||||
- Cross-user operational visibility is intentionally separated from normal task mutation and technical debugging surfaces.
|
||||
|
||||
## Supersedes
|
||||
|
||||
- The implicit administrator-only, organization-shared account behavior of the earlier control-plane baseline.
|
||||
|
||||
## Related
|
||||
|
||||
- `control-plane/migrations/015_account_roles_and_task_audit.sql`
|
||||
- `control-plane/migrations/016_team_lead_operations_dashboard.sql`
|
||||
- `control-plane/migrations/017_user_business_route_authorizations.sql`
|
||||
- `.project-docs/30-worklog/tasks/20260901-account-system-impl-d4e7a2.md`
|
||||
@@ -10,6 +10,7 @@
|
||||
| RELEASE-001 | Current artifacts, filenames, versions, and SHA-256 values are defined only by `dist/release-manifest.json`. | Active | 2026-08-28 | Release and delivery | [Release manifest](../../dist/release-manifest.json) |
|
||||
| SAFETY-001 | Real ERP access/write, task mutation, extension reload, service restart, deployment, and external delivery require explicit task-scoped authorization. | Active | 2026-08-28 | Operations and maintenance | [Governance](../../AGENTS.md) |
|
||||
| NETWORK-001 | In the trusted internal deployment, AgentBus roster attachment URLs may resolve to internal/private addresses; HTTPS, credential rejection, DNS pinning, redirect validation, bounds, and digest checks remain. | Active | 2026-08-31 | AgentBus attachment ingress | [Reply contract](../../agent设计规范/agentbus-reply-contract.md) |
|
||||
| AUTH-001 | The fixed deployment scope uses administrator-managed `admin`, `team_lead`, and `user` accounts, owner-isolated normal tasks, a read-only leadership dashboard, and explicit non-admin task-route allowlists. | Active | 2026-09-01 | Authentication, authorization, audit, and operations oversight | [ADR](AUTH-001-fixed-scope-account-authorization.md) |
|
||||
|
||||
## Superseded Decisions
|
||||
|
||||
|
||||
Reference in new issue
Block a user