Loading…
Three-plane auth model, guards API, and permission enforcement.
Platform · 6 articles
Platform, Tenant, and Consumer auth planes with role hierarchies and permission matrices.
Role guards, RBAC engine with 18 resources, cross-tenant validation, and 122 assertTenantOwnership sites.
SUPPORT/OPS/BILLING/SUPER_ADMIN permissions, route filtering, and impersonation.
7-role hierarchy, DEFAULT_PERMISSIONS matrix, permission overrides, temporary elevation, and IP allowlisting.
requireCustomer, requireOrCreateCustomer, IDOR prevention with household and delegation checks.
Kiosk device fingerprint auth, hardware serial auth, and org-scoped device tokens.
Full help center access with contextual in-app guidance, search, and video tutorials.