Role-based access for enterprise
spec-0042 · drafted 2026-04-22 · author BuildFR
// problem
Admin-only actions can't be restricted from viewer-role users, blocking
enterprise rollout at 12+ accounts.
// segment
Admins at customer orgs ≥ 50 seats, Enterprise & Business tiers.
// acceptance criteria
✓ Admin can define custom roles with scoped permissions
✓ Viewer role blocked from billing, exports, user mgmt
✓ All permission changes emit audit-log events
// success metric
Unblock ≥ 6 of 12 stalled enterprise rollouts within 60 days of ship.
// citations · 47 sources
[gong-2041] Northwind · "We need RBAC before rollout" — 2d ago
[zd-18203] Pied Piper · "Restrict admin actions from viewers?" — 3d ago
[sf-acc-9912] Umbra · "Blocking 6-figure expansion" — 6d ago
+ 44 more