Roles and permissions
Who can see what, and who can approve a change.
The roles
Owner sees everything including billing. Admin manages the workspace and its people. Member works on findings and fixes. Viewer reads. A RuahTech engineer acting on a managed ticket is a role of its own and every action they take is in your audit log under their name.
Permission is checked at the route, deny-by-default: an endpoint that names no permission is refused rather than allowed.
Delegation
You can grant somebody a role temporarily — for an incident, an audit or a holiday — with an expiry. It ends by itself, and everything done under it is marked as delegated rather than being indistinguishable from the person’s own actions.