feat(18-01): add phishing permission resource + role grants

- statement gets the full D-05 vocabulary now: read/analyze/approve/remediate
- superAdminRole and adminRole grant read+analyze
- userRole grants read only (cannot trigger /analyze)
- approve/remediate declared but ungranted to any role until Phase 20
This commit is contained in:
lorentz 2026-07-15 19:23:09 -04:00
parent da926bbe97
commit 04ec51f370

View file

@ -28,6 +28,10 @@ export const statement = {
// Datto RMM Overshell evidence (Phase 4.2 — read jobs / execute scripts)
rmm: ["read", "execute"],
// Phishing triage campaigns/reports (Phase 18 — D-05: full vocabulary now;
// approve/remediate ungranted to any role until Phase 20)
phishing: ["read", "analyze", "approve", "remediate"],
} as const;
// Create access control instance
@ -44,6 +48,7 @@ export const superAdminRole = ac.newRole({
settings: ["read", "update"],
itglue: ["read", "write"],
rmm: ["read", "execute"],
phishing: ["read", "analyze"], // approve/remediate ungranted until Phase 20
});
// Admin role - access to admin panel and user management, but not role management
@ -57,6 +62,7 @@ export const adminRole = ac.newRole({
settings: ["read"],
itglue: ["read", "write"],
rmm: ["read", "execute"],
phishing: ["read", "analyze"],
});
// User role - basic access
@ -70,6 +76,7 @@ export const userRole = ac.newRole({
settings: [],
itglue: ["read"],
rmm: ["read"],
phishing: ["read"], // cannot trigger /analyze
});
// Helper function to check if a user has a specific permission