TM
Governance · Leeu Workspace

Roles & Permissions

Role and permission matrix. Roles are modeled separately from profiles, scoped (global / suite / module / tenant / project / route / action / data_record), and bound through dedicated assignment records.

LEEU Mode: DEV_OBSERVE_ONLY14 roles
LEEU Mode DEV_OBSERVE_ONLY. Development is not constrained by live LEEU Execution Governor authority. LEEU Execution Governor controls are being built, simulated, tested, and audited in sandbox. Production external effects remain gated.
Future posture note
Roles are modeled separately from profiles. Future RLS should use dedicated user_roles and tenant_memberships tables and a SECURITY DEFINER has_role() check. This page is mock-only — no enforcement is wired.

LLM Orchestrator Selector

Frontend-only routing intent — no live provider calls
Mock selector — no provider callOrchestrator: Local / Mock
Local / Mock. Local mock lane. Deterministic, offline. No external effects.
liveApiEnabled: false · boundary: none · next: Use for UI/workflow simulation

Roles & Permissions

Frontend mock · external effects gated
RoleScopeApplies toAllowed actionsBlocked actionsExternal-effect boundaryStatusNext action
Founder Operatorglobalglobalall_global_read, all_global_write, mode_change, production_gate—production_gatedactiveHolds production gate authority
Platform Adminglobalglobal (internal)registry_admin, audit_read, identity_manage—sandbox_simulatedactiveBind to internal admins only
Suite Adminsuiteper-suitesuite_config, module_enable, role_bind_in_suite—sandbox_simulatedplannedDefine per-suite admin scope
Module Operatormoduleper-modulemodule_run, module_read, propose_action—proposal_onlyplannedWire module-scoped policies
Developer OperatorglobalDev Control Roomdev_console_read, dev_console_write_local, propose_releaseproduction_release, external_api_callsandbox_simulatedactiveDev Control Room access for internal builders
Finance ReviewersuiteFinTech Suitefinance_read, review_commentlive_trade_executeproposal_onlyplannedBind Trade Admiral review pack
Construction PMmoduleConstruction Opsproject_read, project_update, subcontractor_assignfinance_write, tenant_admin, production_releaseproposal_onlyplannedBind to Maddison Homes tenant
Subcontractorprojectassigned project entitytask_read, task_update_self—proposal_onlyplannedScope to project entity only
Client Viewerprojectclient-shared projectproject_read_shared—proposal_onlyplannedRead-only client portal scope
Investor Viewertenantinvestor packinvestor_pack_read—proposal_onlyplannedRead-only investor pack
Lender Reviewertenantlender review packlender_pack_read, review_comment—proposal_onlyplannedRead + comment scope
Hashley Agentglobalexecutive assistant lanesummarize, draft_proposal, route_to_human_reviewexecute_external_effect, production_releaseproposal_onlyactiveNo execution authority — proposals only
Codex Workerglobalimplementation lanerepo_read, propose_patch—proposal_onlyactiveManual handoff lane — prompt packets only
Lovable BuilderglobalUI builder laneui_read, ui_propose_change—proposal_onlyactiveBound by approved contract scope

Hashley summary

What
Founder Operator · scope=global
Why it matters
Applies to global. Permissions: all_global_read, all_global_write, mode_change, production_gate.
Current mode
DEV_OBSERVE_ONLY
Lane
Local / Mock
Local/Mock or Live
local/mock
Boundary
production_gated
Next action
Holds production gate authority
Actions are local UI only. No external effects. No provider calls.

External-effect boundary

Channels, proposals, and manifests do not grant execution authority.

External-effect work remains proposal-only until LEEU admission. Production gate is not active.

DEV_OBSERVE_ONLY · mock_only · external_effect_gated — production enforcement not wired.