Authorization (Planned)¶
This document describes the planned authorization model. It is not implemented in the current scaffold.
Planned approach¶
- Scope-based authorization on protected endpoints
- Client definitions bound to
company_idandorganization_id - Payload tenant fields compared against authenticated client scope
- Preparation for IP allowlists and rate limits
Planned examples¶
| Capability | Planned scope |
|---|---|
| Inbound work-order write | inbound.write |
| Future delete operations | Separate privileged scope |
Authorization must fail closed when auth is enabled.