Handover workspace

ERS, Todo, OfferReview, and Docu in one view

Imported from live server docs, code structure, and deployment notes.

Sep 28, 2026, 9:08 AM

OfferReview

RBAC & Permissions

No summary found yet.

docs/07-rbac-permissions.md

Updated Aug 28, 2026, 8:07 AM

Codex 5.3 Refactor Note: Canonical refactor plan: docs/CODEX-5.3-REFACTOR-PLAN.md. This document is retained for historical and implementation context during the refactor.

RBAC & Permissions

Current source of truth

Role summary

  • HR
    • works intake, HR screening, manager assignment, and supporting candidate operations
    • can access upload flow and parts of org/admin-style tooling in the current worktree
  • MANAGER
    • candidate access is assignment-based
    • can also review through /manager-review/[token] when a valid link exists
  • SMO
    • owns the decision workspace across every active candidate, including upstream HR/manager stages
    • can complete HR screening, assign a manager, complete manager review, resend/waive a deep-dive questionnaire, progress a candidate to SMO decision, and finalize a decision
    • every direct progression or waiver requires a decision note and is recorded in the candidate audit trail
  • ADMIN
    • owns system settings, governance, access requests, user administration, and org configuration

Important current caveats

  • Manager dashboard still surfaces some unassigned HR_SCREENED items even though detail access remains assignment-locked.
  • Settings is visible in the shared nav, but the main settings APIs are admin-only.
  • HR can open the users list, but user-detail access is currently narrower than the list permission.