Preparing payment page…
Roles & permissions
Two independent axes — a platform System role and a per-project role — with authorization always checked against permission strings, never role names.
System roles govern the operator surface; project roles govern a single project. A key on the machine axis never carries system permissions.
Endpoints declare the permission they require; role names live in exactly one bundle table you can edit without touching a controller.
Owner ⊃ Admin ⊃ Member ⊃ Viewer on the project axis; five named System roles compose by union — no custom roles to reason about.
A single platform:override permission is the only cross-tenant bypass, and every use is written to the audit log.
Sign in and create your first project in under two minutes.