Title: Identity and Access Control Version: 1.0 Owner: [TENANT_CONFIGURATION_REQUIRED — Security Architecture] Status: Draft Last reviewed: 2026-09-07 Next review: [TENANT_CONFIGURATION_REQUIRED] Reviewers: Security, Architecture, HR
Defines RBAC and ABAC controls implementing the roles in personas-and-roles.md and the scopes in hr-onboarding-api.openapi.yaml.
Roles carry a fixed set of scopes (see the OpenAPI securitySchemes.oauth2.flows.authorizationCode.scopes list). Role-to-scope mapping is configuration, not code — see config/tenants/sample-tenant.yaml.
Every request additionally carries attribute context evaluated against the resource: tenant_id, department, location, business_unit, grade. A recruiter role, for example, is further scoped to the departments/locations they are assigned (user_role_assignment.scope in sample-relational-schema.sql).
| Role | TAN approve | Shortlist approve | Offer approve | Discrepancy resolve | Employee convert | Audit read |
|---|---|---|---|---|---|---|
recruiter |
✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
hiring_manager |
✗ | Configurable (co-approve) | ✗ | ✗ | ✗ | ✗ |
hr_approver |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
interviewer |
✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
hr_ops |
✗ | ✗ | ✗ | ✗ (request re-upload only) | ✗ | ✗ |
compliance_reviewer |
✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
platform_admin |
✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
agent_service_principal |
✗ (may propose only) | ✗ (may propose only) | ✗ (may draft only) | ✗ | ✗ | ✗ |
hr_approver, platform_admin, and compliance_reviewer roles — [TENANT_CONFIGURATION_REQUIRED] enforcement point (IdP conditional access policy).Access tokens are short-lived (default 15 minutes — [TENANT_CONFIGURATION_REQUIRED]); refresh tokens rotate on use. Tokens are never logged (see logging-and-redaction-standard.md).
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 2026-09-07 | Documentation package generation | Initial creation |