5.4 KiB
5.4 KiB
Manager Phase 0 — Role, permission, and data-scope audit
Scope lock
Files expected to change
backend/app/Modules/Identity/Application/RolePermissions.phpbackend/app/Modules/Learner/Http/LearnerController.php- Manager and identity authorization tests
- This audit document
Modules affected
- Identity permissions
- Manager workspace read model
- Team and user visibility
- Personal learner experience shared by learners and managers
API endpoints affected
GET /api/v1/learner/home- Learner assignment/player endpoints under
/api/v1/learner/* GET /api/v1/manager/workspaceis audited and tested; its response contract is unchanged.
Permissions affected
- Managers gain
learning.personal.viewfor learning assigned to their own account. - Managers retain team-scoped read permissions.
- Managers do not gain course authoring, organization assignment management, user management, platform administration, or organization-wide analytics.
Expected behavior changes
- A manager may consume courses and learning paths assigned to the manager's own user account.
- Personal-learning queries continue to resolve the authenticated user's assignment only.
Behavior that must remain unchanged
- Learner personal learning remains functional.
- Manager team analytics remains restricted to explicitly managed teams.
- Course Designer and Super Admin capabilities are unchanged.
- Manager UI is not redesigned in Phase 0.
Current authorization model
The application stores one primary role per user. A Manager therefore receives the learner capability needed for self-learning through a permission, without adding a second role or duplicating the learner domain. The same learner endpoints and course player are reused.
Manager team scope is the union of members belonging to teams explicitly linked through team_managers, constrained again by organization_id. Direct reports are automatically attached when a designer assigns a manager to a team; a direct-report relationship alone is not treated as an implicit organization-wide grant.
Permission matrix
| Capability | Manager | Enforcement |
|---|---|---|
| View own assigned learning | Yes | learning.personal.view; assignment must contain authenticated user |
| Continue own course/player activity | Yes | Assignment, organization, course-version, lesson, and user scope |
| View explicitly managed teams | Yes | teams.view plus team_managers membership |
| View members of managed teams | Yes | User directory and manager workspace team scope |
| View team learning progress | Yes | analytics.team.view and managed member IDs |
| View team assessments | Yes | Manager workspace uses managed member IDs |
| View team skills taxonomy | Yes, read-only | taxonomy.view |
| View organization-wide users | No | User directory narrows Manager to managed-team members |
| View another team's private data | No | Managed team/member ID filters |
| View another user's personal assignment/player | No | Learner progress resolves assignment through authenticated user |
| Create or edit a course | No | courses.author denied |
| Use Course Builder, Question Bank, or AI Studio | No | courses.author denied |
| Create organization assignments | No in Phase 0 | assignments.manage denied |
| Create/update/delete teams or users | No | teams.manage and users.manage denied |
| Export organization data | No | Export endpoints require courses.author |
| View organization monitoring | No | analytics.organization.view denied |
| Manage subscription/settings/platform | No | Relevant organization/platform permissions denied |
| Approve requests | Not implemented | No approval capability or workflow currently exists |
Endpoint audit summary
- Manager workspace aggregation begins from managed team IDs, then member IDs, and applies the tenant organization to teams, assignments, events, and assessments.
- User listing uses
UserDirectory::visibleTo, which limits a Manager to users in managed teams. - Team index/detail limits a Manager to teams where the Manager is explicitly attached.
- Team, user, assignment, course, builder, assessment-authoring, export, monitoring, AI, and platform mutations require permissions the Manager does not have.
- Personal learner endpoints now authorize by
learning.personal.view; all reads and mutations remain bound to the authenticated user's own assignment.
Security checks
- Cross-team Manager workspace data: covered.
- Unmanaged team detail by ID: covered.
- Organization-wide user listing: denied by scoped directory query.
- Unauthorized team mutation: covered.
- Unauthorized assignment/course mutation: covered.
- Another user's personal assignment ID: returns not found.
- Cross-tenant records: tenant middleware and organization filters remain required.
- Frontend menu hiding is not treated as an authorization control.
Deferred technical debt
Medium
- The Manager frontend route guard currently accepts only
/manager/*; exposing the shared learner UI inside Manager navigation belongs to Phase 1. - Assignment creation for a Manager is intentionally still denied. A team-scoped assignment permission and recipient resolver belong to Phase 3.
Low
- Approval workflows and permission names do not exist yet; they should only be introduced if the product workflow is implemented in Phase 4.
- Manager report export is not available. Any future export must resolve recipients and rows from managed-team scope on the backend.