Workspace tabs
Security
Review role access across pages, data, and endpoints.
The Security tab turns Domain roles into an access-control matrix across the surfaces planned in Structure, Data, and Backend.
Define the axes first
Create roles in Domain → Roles. Pages, entities, and API endpoints form the other axis automatically. If no roles exist, Security provides a direct path back to the Roles panel.
Set the policy
Choose the default access policy, then record exceptions for individual role-and-resource pairs. You can fill the matrix manually or generate a starting policy from the project description.
Role guards placed in Structure's Navigation view appear as derived denials. Removing a guard removes that derived restriction immediately.
Security is a planning and reporting surface: its matrix is saved with the project and included in the project report.