ai-enabled-hr-talent-automation

Identity and Access Control

Title: Identity and Access Control Version: 1.0 Owner: [TENANT_CONFIGURATION_REQUIRED — Security Architecture] Status: Draft Last reviewed: 2026-09-07 Next review: [TENANT_CONFIGURATION_REQUIRED] Reviewers: Security, Architecture, HR

Purpose and scope

Defines RBAC and ABAC controls implementing the roles in personas-and-roles.md and the scopes in hr-onboarding-api.openapi.yaml.

RBAC model

Roles carry a fixed set of scopes (see the OpenAPI securitySchemes.oauth2.flows.authorizationCode.scopes list). Role-to-scope mapping is configuration, not code — see config/tenants/sample-tenant.yaml.

ABAC model

Every request additionally carries attribute context evaluated against the resource: tenant_id, department, location, business_unit, grade. A recruiter role, for example, is further scoped to the departments/locations they are assigned (user_role_assignment.scope in sample-relational-schema.sql).

Access matrix (role × sensitive action)

Role TAN approve Shortlist approve Offer approve Discrepancy resolve Employee convert Audit read
recruiter ✗ ✗ ✗ ✗ ✗ ✗
hiring_manager ✗ Configurable (co-approve) ✗ ✗ ✗ ✗
hr_approver ✓ ✓ ✓ ✓ ✓ ✓
interviewer ✗ ✗ ✗ ✗ ✗ ✗
hr_ops ✗ ✗ ✗ ✗ (request re-upload only) ✗ ✗
compliance_reviewer ✗ ✗ ✗ ✗ ✗ ✓
platform_admin ✗ ✗ ✗ ✗ ✗ ✓
agent_service_principal ✗ (may propose only) ✗ (may propose only) ✗ (may draft only) ✗ ✗ ✗

Authentication requirements

Session and token handling

Access tokens are short-lived (default 15 minutes — [TENANT_CONFIGURATION_REQUIRED]); refresh tokens rotate on use. Tokens are never logged (see logging-and-redaction-standard.md).

Change control

Version Date Author Change
1.0 2026-09-07 Documentation package generation Initial creation