Modules
User Management
Users, roles, and scoped access control.
User Management owns identity and authorization:
- Users & organizations — org users plus cross-tenant system users.
- Roles & permissions — RBAC via
@Permissions({ moduleCode, featureCode, permissionType })checks on protected endpoints. - Access levels — each permission is scoped (
OWN,ALL,TEAMS,REGIONS,BUSINESS_UNIT) so the same role sees different rows depending on the user's team, region, or business unit.
System users can enter simulation to act inside a specific tenant, which is audited. See Auth & JWT.