← Pack index
Phase 1 · Deliverable 06 of 10

Role visibility and action-permission matrix

Least privilege by default. Visibility answers "what data can this role see"; action rights answer "what can this role do". The lens never widens either. AI inherits the requester's scope and holds no action rights.

DRAFT v0.1 · FOR APPROVAL AUTHORITY LIMITS: PLACEHOLDER (DoA)

6a · Visibility (data scope)

Full = all entities. Own = own entity only. Domain = assigned function within own entity. Assigned = only items assigned to the user. Summary = aggregated, no transaction rows. Material = only items at or above the materiality threshold. — = not rendered (D-12).

Information domain
OWN
CGE
ENX
FNL
MOC
ANL
ACO
INC
ASR
ADM
AI
Lenses available
Owner (+ Core Group read: D-21)
Core Group + Entity (any in scope)
Entity (own)
Entity (domain)
Assurance views in scope
Scoped views
Entity (assigned)
Incident scope
Assurance views
None (admin console)
Requester's
Group and portfolio KPIs
Full · summary
Full
—
—
Assigned KPIs
Assigned
—
Incident-linked
Review scope
—
Requester's
Peer-entity comparison
Full
Full
— (D-16)
—
—
Assigned
—
—
Review scope
—
Requester's
Entity and plant performance
Summary to plant
Full to plant; line on drill
Own, to line
Domain, to line
Assigned
Assigned
Assigned
Incident scope
Review scope
—
Requester's
Transaction and reconciliation records
—
Counts only
Own
Domain
Assigned
Assigned
—
—
Review scope
Mappings metadata
Requester's
Cash upstreaming and group treasury
Full
Full
Own obligation (C-05)
Finance domain
Assigned
Assigned
—
Incident-linked
Review scope
—
Requester's
Alerts and cases
Material only
All material + entity summaries
Own
Domain
Linked to own KPIs
Assigned
Assigned
Incident
Review scope
—
Requester's
Risk, compliance, EHS, audit findings
Material summary
Full
Own
Domain
—
Assigned
Assigned
Incident
Full in scope
—
Requester's
Certification, lineage, evidence
Status only
Governance view
Own status
Domain status
Full in scope
Full in scope
Own evidence
Incident evidence
Full in scope
Mapping lineage only
Requester's
War rooms
View all active (critical)
View and coordinate
Own entity
If member
—
If member
If member
Full
View
—
—
Disclosure-review state
View
View
—
—
—
—
—
View
View
—
—
AI explanations, briefs, Ask
Own scope
Own scope
Own scope
Own scope
Own scope
Own scope
Own scope
Own scope
Own scope
—
Never exceeds requester

6b · Action permissions

YesPermitted
ScopeOnly within assigned scope or authority
ReqMay request or recommend only
DraftAI drafts for human acceptance
—Not permitted; control not rendered
#
Action
OWN
CGE
ENX
FNL
MOC
ANL
ACO
INC
ASR
ADM
AI
01
View and acknowledge alert (not ownership)
Yes
Yes
Scope
Scope
Scope
Scope
Scope
Scope
Yes
—
—
02
Accept ownership
—
Req
Scope
Scope
—
—
Scope
Scope
—
—
Draft
03
Assign supporting action
—
Scope
Scope
Scope
—
—
Req
Scope
—
—
Draft
04
Update status
—
Scope
Scope
Scope
—
Scope
Scope
Scope
—
—
—
05
Attach evidence
—
Scope
Scope
Scope
Scope
Scope
Scope
Scope
Scope
—
—
06
Run scenario
Req
Yes
Scope
Scope
—
Scope
—
Scope
—
—
Draft
07
Publish scenario as decision basis
—
Yes
Scope
—
—
—
—
Req
—
—
—
08
Escalate
Req
Yes
Req
Req
Req
Req
Req
Yes
Req
—
Draft
09
Open war room
Req
Yes
Req
—
—
—
—
Yes
—
—
—
10
Intervene in critical escalation
Yes
Req
—
—
—
—
—
—
—
—
—
11
Make permitted strategic decision
Scope
Scope
Scope
—
—
—
—
—
—
—
—
12
Request analysis
Yes
Yes
Yes
Yes
—
—
—
Yes
Yes
—
—
13
Draft executive update
—
Yes
Scope
Scope
—
—
—
Yes
—
—
Draft
14
Approve communication (Core Group / Owner update)
—
Yes
Scope
—
—
—
—
Req
—
—
—
15
Request closure
—
—
Req
Req
—
—
Req
Req
—
—
—
16
Approve or reject closure (D-06 tiers)
—
Scope
Scope
Scope
—
—
—
—
Req
—
Check
17
Reopen closed case
Req
Yes
Req
—
—
—
—
—
Yes
—
—
18
Certify KPI
—
—
—
—
Scope
—
—
—
—
—
Check
19
Certify with exception
—
—
—
—
Scope
—
—
—
—
—
Check
20
Request data correction
—
Req
Req
Req
Yes
Req
—
—
Req
—
Check
21
Approve KPI override (D-17)
—
—
—
—
Scope
—
—
—
Req
—
—
22
Maintain approved mappings / config
—
—
—
—
Req
—
—
—
—
Scope
—
23
Accept material risk
Scope
Scope
Req
—
—
—
—
Req
—
—
—
24
Approve disclosure (Disclosure Authority — PLACEHOLDER)
—
Req
—
—
—
—
—
Req
Req
—
—
25
Release daily Owner brief
—
Yes
—
—
—
—
—
—
—
—
Draft
26
Maintain live facts in war room
—
Req
Req
Req
—
Req
—
Yes
—
—
Draft
27
Approve permitted local action within [DoA — PH] (v0.2)
—
—
Scope
Scope
—
—
—
—
—
—
—
28
Add business explanation or comment (v0.2)
—
Yes
Scope
Scope
Scope
Scope
Scope
Scope
Scope
—
Draft
29
Document action dependency (v0.2)
—
Scope
Scope
Scope
—
—
Scope
Scope
—
—
—
30
Maintain decisions log and communication drafts (v0.2)
—
Scope
—
—
—
—
—
Yes
—
—
Draft
31
Review, sample, challenge certification / controls / evidence / overrides / closure (v0.2)
—
Req
—
—
—
—
—
—
Yes
—
Check
32
Certify consolidated group-scope KPI (v0.2, D-22)
—
—
—
—
Scope
—
—
—
—
—
Check

6c · Hard governance rules (enforced in UI and service)

GR-01
AI has no approval authority
AI cannot certify a KPI, approve a financial number, accept material risk, approve disclosure, close a material case or assign accountability. AI-originated items carry an 'AI draft' tag until a human accepts them. Approval controls are never pre-filled.
GR-02
No self-approval of closure
The action owner and the closure approver must be different users unless an explicit, audited authorisation exists.
GR-03
Certification within scope only
A certifier sees certification controls only for KPIs and nodes assigned to them. For leadership KPIs, the metric owner may not also certify (D-02).
GR-04
Administrator has no business authority
A mapping or config change moves the affected KPIs to 'Pending certification' and writes an audit entry. Admin has no certify, accept-risk or close controls.
GR-05
Assurance is read-only on business data
The Assurance Reviewer may comment, challenge, sample and reopen, but never edits values, actions or evidence.
GR-06
Lens never widens scope
Switching lens changes depth and layout only. Entitlement scope is applied before render, search, AI and notification.
GR-07
Core Group cannot alter source facts
Core Group coordinates, routes, escalates and governs. Facts change only by source correction and re-certification.
GR-08
Owner visibility is gated by materiality
Push to the Owner only at or above [OWNER THRESHOLD — PLACEHOLDER]. Pull below the threshold is labelled 'Below materiality threshold' (D-04).
GR-09
No leakage through restricted states
Restricted items show no values, counts, names or titles outside parent scope. Search and Ask never confirm that they exist (D-12).
GR-10
Every write is audited
Acceptance, decision, certification, override, escalation, evidence, communication approval, closure and reopen are recorded with role, time, rationale and prior state.