From 80e71297405a0e3e3a720fbc8150fdfcbf142d70 Mon Sep 17 00:00:00 2001 From: lorentz Date: Thu, 16 Jul 2026 10:43:18 -0400 Subject: [PATCH] feat(20-02): grant phishing approve+remediate to admin roles (D-02) - superAdminRole and adminRole now include "approve" and "remediate" for phishing - userRole unchanged (still read-only) --- lib/permissions.ts | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/lib/permissions.ts b/lib/permissions.ts index a1a3e3b..e494930 100644 --- a/lib/permissions.ts +++ b/lib/permissions.ts @@ -29,8 +29,7 @@ export const statement = { // Datto RMM Overshell evidence (Phase 4.2 — read jobs / execute scripts) rmm: ["read", "execute"], - // Phishing triage campaigns/reports (Phase 18 — D-05: full vocabulary now; - // approve/remediate ungranted to any role until Phase 20) + // Phishing triage campaigns/reports (Phase 18 — D-05: full vocabulary) phishing: ["read", "analyze", "approve", "remediate"], } as const; @@ -48,7 +47,7 @@ export const superAdminRole = ac.newRole({ settings: ["read", "update"], itglue: ["read", "write"], rmm: ["read", "execute"], - phishing: ["read", "analyze"], // approve/remediate ungranted until Phase 20 + phishing: ["read", "analyze", "approve", "remediate"], }); // Admin role - access to admin panel and user management, but not role management @@ -62,7 +61,7 @@ export const adminRole = ac.newRole({ settings: ["read"], itglue: ["read", "write"], rmm: ["read", "execute"], - phishing: ["read", "analyze"], + phishing: ["read", "analyze", "approve", "remediate"], }); // User role - basic access