Layer 01
Access Control
Roles decide which pages a person can open. Ownership-scoped permissions go further, deciding which records they see once they're there - none, only their own, only what they added, both, or all. Condition-based RBAC guardrails enforce the dependencies a permission grid should always have, refusing a save that doesn't make sense rather than silently applying it.
Built in
- Entrust roles plus custom fine-grained permissions
- Ownership-scoped visibility per module
- Guardrails that refuse incoherent permission saves