WzGate
Concepts

Permissions

RBAC plus per-permission access levels.

Authorization combines two layers:

  1. RBAC — protected endpoints declare the permission they require via a @Permissions({ moduleCode, featureCode, permissionType }) decorator, enforced by auth + permission guards. Endpoints can opt out as public.
  2. Access levels — each granted permission also has a scope: OWN, ALL, TEAMS, REGIONS, or BUSINESS_UNIT. The scope decides which rows the user sees, using the ownership fields on each model.

So "can this user call the endpoint?" (RBAC) and "which records do they see?" (access level) are answered separately and combined.