Governator
Theme

Help

Specification state 39457a1
A18

Roles and permissions

Unit E1 · Screens M21 · MCP identitaet_liste, identitaet_lesen, identitaet_anlegen, identitaet_aendern, rolle_zuweisen, rolle_entziehen, wer_bin_ich · Status Approved (2026-09-07)

  • AC1 Roles: User, Responsible Author, Contributing Author, Reviewer, Approver, Administrator. A permission matrix (use case × role) is provided in docs/architektur.md and is verified by a test against the service layer.
  • AC2 Roles are assigned from IDP claims via the mapping layer (N10) and additionally internally by administrators; the source of each assignment is visible (F28).
  • AC3 Administrators create agent identities; agents have no OIDC login.
  • AC4 wer_bin_ich returns the caller's identity, actor type, roles and effective scopes.
  • AC5 The first administrator is determined via an installation parameter (OIDC subject or e-mail).