Access Console

Auth bootstrap and RBAC policy

Review first-admin requirements, root roles, MFA posture, API token constraints, and Phase 1 permission coverage.

RBAC-ready

system.owner

platform

Owns installer, licensing, updates, security, and tenant recovery.

security.admin

tenant

Manages audit, security events, token policy, and recovery controls.

tenant.owner

tenant

Manages company users, roles, branches, and tenant settings.

Access Policies

MFA for system owner
Required
MFA for recovery
Required
API tokens
Hashed
Token expiry
90 day default

Phase 1 Permissions

installer.manage
license.manage
updates.manage
security.view
security.manage
security.audit.export
identity.manage
tenants.manage
users.manage
roles.manage
api_tokens.manage