Primary role lane
AcceptedTechnical details
brand_pointerpartner://innovate/brand/lab/v2026-05-01asset_pointerhttps://assets.innovate.test/pci/brand_reasonsnone
Partner brand service
Loading partner-owned brand manifest from /api/session/brand.
- Brand API
/api/session/brand- Boundary
- No browser tenant authority, brand override authority, theme mutation, asset upload, endpoint value, account identifier, physical id, secret, live-data path, or fallback browser storage.
Trusted tenant context
Tenant authority: trusted API session
Tenant: pci_tnt_innovate_lab; partner: innovate; stage: lab; registry version: 3.
No viewer authority inputs were used.
auth.session_refreshed
Module status
- Data Collection enabled / primary Data Collection is enabled by trusted session context.
- Monitoring enabled / integrated Monitoring is enabled by trusted session context.
Server-derived role map
Users & roles renders the server permission matrix already issued for this session. The browser cannot create users, change roles, invite principals, or choose tenant/entity scope.
Server roles
AcceptedEntity scope refs
AcceptedVisible actions are mounted from server metadata. Hidden actions are summarized by category and never become browser controls.
- Roles
pci_operator- Entity scope
ent_innovate_platform_lab- Source path
/api/permissions/matrix
Matrix authority
matrix_sourceapi_server_derived_from_session_registry_contextprimary_rolepci_operatorserver_rolespci_operatorserver_entity_scopeent_innovate_platform_labviewer_role_input_acceptedfalseviewer_entity_input_acceptedfalsebrowser_authoritynone
Visible server actions
This screen lists only actions exposed as visible, allowed, and enabled by the server-derived matrix. It does not create invite, user, role, auditor, QSA, queue, or notification controls in the browser.
| Action | Category | Status | Browser implication |
|---|---|---|---|
Review tenantAction refs
|
tenant | Accepted | Server-authorized display metadata. |
Review evidence packageAction refs
|
evidence | Accepted | Server-authorized display metadata. |
Create evidence metadata intakeAction refs
|
evidence | Accepted | Server-authorized display metadata. |
Answer questionnaireAction refs
|
assessment | Accepted | Server-authorized display metadata. |
Override inherited answerAction refs
|
assessment | Ready for review | Server step-up required before service mutation. |
Invite submerchantAction refs
|
onboarding | Accepted | Server-authorized display metadata. |
Save workflow stateAction refs
|
workflow | Accepted | Server-authorized display metadata. |
Queue audit exportAction refs
|
audit | Ready for review | Server step-up required before service mutation. |
document action(s) not mounted
Fail-closed — lockedHidden action summary
hidden_action_count1hidden_categoriesdocument:1never_allowed_behaviorhidden_not_disabledcross_scope_actions_emittedfalse
Route visibility projection
Hidden routes are removed from the shell instead of becoming browser-side controls. This table is derived with the same route visibility function used by navigation.
| Screen | Canonical path | Phase | Implication |
|---|---|---|---|
DashboardRoute visibility source
|
/ |
Dashboard | AcceptedMounted in shell navigation for this matrix. |
Tenant & modulesRoute visibility source
|
/tenant-modules |
Set up | AcceptedMounted in shell navigation for this matrix. |
ComplianceRoute visibility source
|
/compliance |
Assess | AcceptedMounted in shell navigation for this matrix. |
Assessment workspaceRoute visibility source
|
/assessment-workspace |
Assess | AcceptedMounted in shell navigation for this matrix. |
Review & remediationRoute visibility source
|
/review/remediation |
Review | AcceptedMounted in shell navigation for this matrix. |
Reports & exportsRoute visibility source
|
/reports/exports |
Deliver | AcceptedMounted in shell navigation for this matrix. |
Evidence libraryRoute visibility source
|
/evidence-library |
Assess | AcceptedMounted in shell navigation for this matrix. |
AOC review & exportRoute visibility source
|
/documents/aoc-review |
Deliver | AcceptedMounted in shell navigation for this matrix. |
Audit timelineRoute visibility source
|
/audit/timeline |
Admin | AcceptedMounted in shell navigation for this matrix. |
Corpus versionsRoute visibility source
|
/corpus/versions |
Admin | AcceptedMounted in shell navigation for this matrix. |
Users & rolesRoute visibility source
|
/users-roles |
Admin | AcceptedMounted in shell navigation for this matrix. |
Brand & themeRoute visibility source
|
/brand-theme |
Admin | AcceptedMounted in shell navigation for this matrix. |
Workflow tasksRoute visibility source
|
/workflow/tasks |
Set up | AcceptedMounted in shell navigation for this matrix. |
Monitoring readinessRoute visibility source
|
/monitoring-readiness |
Review | AcceptedMounted in shell navigation for this matrix. |
Acceptance flowRoute visibility source
|
/acceptance-flow |
Admin | AcceptedMounted in shell navigation for this matrix. |
Admin authority boundaries
No user creation, role editing, principal invitation, auditor/QSA enablement, queue send, notification send, or tenant/entity selection is mounted in this browser screen.
- Accepted Server-derived session, roles, and entity scope only.
- Fail-closed — locked Browser-created principals, role changes, invite creation, and user provisioning are not mounted.
- Fail-closed — locked Invite authority remains server/operator-owned; visible invite metadata does not create a browser invite action.
- Accepted Same-origin
/api/permissions/matrixread policy; no request body, query authority, or browser storage fallback.
Boundary refs
request_policytrusted-session-no-query-no-body-no-viewer-role-entity-signer-authoritybrowser_authoritynonetenant_authoritytrusted-api-session-service sampleshell_routeusersRoles