Skip to main content
Permissions in SpineWorkspace combine roles, scopes, and capability-level authorization. A user’s role sets what they can see. A connection’s scope sets what a source system exposes. A capability’s authorization gates every action before it runs.

The Model

  • Roles — who can view or work each domain and view.
  • Scopes — which parts of a source system a connection can read or write.
  • Capability authorization — which actor can invoke which capability under which policy.