Skip to content

Roles & Permissions

Seeing the same work does not mean having the same authority.

Nexia treats authentication, organization membership, navigation, and authority as different concerns. When someone requests a protected action, the backend checks the exact Permission, assigned scope, resource conditions, and acting subject.

Authorization checkAllowed by policy
Exact protected action

Permission

Allowed by policy

Exact protected action

Permission names the action. Grant defines where it applies.

People and Agents follow the same rule: explicit authority is required, limited to the current scope, revocable, and never widened by the subject itself.

The backend makes the final authorization decision.

A login, organization chart, selected Legal Entity, open Space or Work Tab, visible button, installed App, assigned business process task, or Agent recommendation is not final authority. Protected operations are allowed or denied in the backend.

Which action needs a clearer authority boundary?