Skip to content

Authorization (Planned)

This document describes the planned authorization model. It is not implemented in the current scaffold.

Planned approach

  • Scope-based authorization on protected endpoints
  • Client definitions bound to company_id and organization_id
  • Payload tenant fields compared against authenticated client scope
  • Preparation for IP allowlists and rate limits

Planned examples

Capability Planned scope
Inbound work-order write inbound.write
Future delete operations Separate privileged scope

Authorization must fail closed when auth is enabled.