Skip to main content

Security & Access Control

RBAC, policies & audit intelligence · loading...

Read this - how security really works here: this page manages roles, permissions and policies (real CRUD in Firestore: roles, team_members, security_policies, audit_log). But a browser page cannot enforce access - anyone can read the page's code. Real enforcement must live in two places you control server-side: (1) Firestore Security Rules that check each user's role before allowing reads/writes, and (2) Cloud Functions for sensitive actions (approvals, refunds). The roles you define here are written to Firestore so your rules/functions can read and enforce them. MFA and device-fingerprinting are enabled at the Firebase Auth / Identity Platform level, not in this file.

Recent Security Events

View full log
EventUserDetailRiskWhen

Roles

Toggle which modules each role can access. Super Admin always has full access (locked). Changes save to the roles collection for your security rules to enforce.

Team Members

MemberRoleBranch / WarehouseMFAStatusLast ActiveActions

Session & Access Policies

IP Allowlist

IP restrictions are enforced server-side (Cloud Functions / Identity Platform). Listed here for configuration; they save to security_policies.

Audit Log

EventUserModuleDetailRiskTimestamp