Governance · Leeu Workspace
Roles & Permissions
Role and permission matrix. Roles are modeled separately from profiles, scoped (global / suite / module / tenant / project / route / action / data_record), and bound through dedicated assignment records.
LEEU Mode: DEV_OBSERVE_ONLY14 roles
LEEU Mode DEV_OBSERVE_ONLY. Development is not constrained by live LEEU Execution Governor authority. LEEU Execution Governor controls are being built, simulated, tested, and audited in sandbox. Production external effects remain gated.
Future posture note
Roles are modeled separately from profiles. Future RLS should use dedicated user_roles and tenant_memberships tables and a SECURITY DEFINER has_role() check. This page is mock-only — no enforcement is wired.LLM Orchestrator Selector
Frontend-only routing intent — no live provider calls
Mock selector — no provider callOrchestrator: Local / Mock
Local / Mock. Local mock lane. Deterministic, offline. No external effects.
liveApiEnabled: false · boundary: none · next: Use for UI/workflow simulation
Roles & Permissions
Frontend mock · external effects gated
| Role | Scope | Applies to | Allowed actions | Blocked actions | External-effect boundary | Status | Next action |
|---|---|---|---|---|---|---|---|
| Founder Operator | global | global | all_global_read, all_global_write, mode_change, production_gate | — | production_gated | active | Holds production gate authority |
| Platform Admin | global | global (internal) | registry_admin, audit_read, identity_manage | — | sandbox_simulated | active | Bind to internal admins only |
| Suite Admin | suite | per-suite | suite_config, module_enable, role_bind_in_suite | — | sandbox_simulated | planned | Define per-suite admin scope |
| Module Operator | module | per-module | module_run, module_read, propose_action | — | proposal_only | planned | Wire module-scoped policies |
| Developer Operator | global | Dev Control Room | dev_console_read, dev_console_write_local, propose_release | production_release, external_api_call | sandbox_simulated | active | Dev Control Room access for internal builders |
| Finance Reviewer | suite | FinTech Suite | finance_read, review_comment | live_trade_execute | proposal_only | planned | Bind Trade Admiral review pack |
| Construction PM | module | Construction Ops | project_read, project_update, subcontractor_assign | finance_write, tenant_admin, production_release | proposal_only | planned | Bind to Maddison Homes tenant |
| Subcontractor | project | assigned project entity | task_read, task_update_self | — | proposal_only | planned | Scope to project entity only |
| Client Viewer | project | client-shared project | project_read_shared | — | proposal_only | planned | Read-only client portal scope |
| Investor Viewer | tenant | investor pack | investor_pack_read | — | proposal_only | planned | Read-only investor pack |
| Lender Reviewer | tenant | lender review pack | lender_pack_read, review_comment | — | proposal_only | planned | Read + comment scope |
| Hashley Agent | global | executive assistant lane | summarize, draft_proposal, route_to_human_review | execute_external_effect, production_release | proposal_only | active | No execution authority — proposals only |
| Codex Worker | global | implementation lane | repo_read, propose_patch | — | proposal_only | active | Manual handoff lane — prompt packets only |
| Lovable Builder | global | UI builder lane | ui_read, ui_propose_change | — | proposal_only | active | Bound by approved contract scope |
Hashley summary
What
Founder Operator · scope=global
Why it matters
Applies to global. Permissions: all_global_read, all_global_write, mode_change, production_gate.
Current mode
DEV_OBSERVE_ONLY
Lane
Local / Mock
Local/Mock or Live
local/mock
Boundary
production_gated
Next action
Holds production gate authority
Actions are local UI only. No external effects. No provider calls.
External-effect boundary
Channels, proposals, and manifests do not grant execution authority.
External-effect work remains proposal-only until LEEU admission. Production gate is not active.
DEV_OBSERVE_ONLY · mock_only · external_effect_gated — production enforcement not wired.