Skip to main content

DigiTrade access roles, permissions, and tool boundaries

DigiTrade separates platform setup from live-shop operation.

N
Written by Niyaz

DigiTrade access separates the identity acting, the actions that identity may attempt, and the business authority required to complete an outcome. A role groups permissions into a reusable access pattern for named responsibilities. A permission authorizes an identity to attempt one material action on a governed resource. An access grant assigns a role or permission to a person or group within a defined scope.

Understand the access model

Authentication establishes who is acting, while authorization determines what that identity may attempt. Effective access depends on the assigned role or permission together with applicable membership, policy, approval, environment, and validity checks. Authorization to attempt an action does not prove that the action or an externally managed business outcome was completed. A role or permission provides access authority but does not transfer capability authority or change the system of record.

Where access is administered

  • The Hub implementer record contains separate Clients and Tools selectors. This separation distinguishes the clients an implementer serves from the tools the implementer may open.

  • A client record separates General Info, Setting Up Automation, and Admin Panel User into separate areas. This separation administers the client's identity apart from the client's own configuration. The Admin Panel User area includes a disabled Roles control displaying Admin.

  • The Admin Panel provides a destination titled Client permissions. The Client permissions destination displays Not Found, contains no fields or tables, and offers Go Back.

Keep application access separate from authorization

The Hub Tools page lists separate Open app links for Admin Panel, Site Builder, and Erp Manager. What an identity may attempt inside an application is decided by the assigned role or permission. Treating an application link as authority inside that application is the common error this distinction prevents.

Evaluate identity and access separately

Knowing who is acting does not by itself determine what that identity may attempt. Effective access therefore depends on the assigned role or permission and the applicable membership, policy, approval, environment, and validity checks.

Hub Tools page listing separate application links for Admin Panel, Site Builder, and Erp Manager

Related

Did this answer your question?