Security & Access Control
RBAC, policies & audit intelligence · loading...
Read this - how security really works here: this page manages roles, permissions and policies (real CRUD in Firestore:
roles, team_members, security_policies, audit_log). But a browser page cannot enforce access - anyone can read the page's code. Real enforcement must live in two places you control server-side: (1) Firestore Security Rules that check each user's role before allowing reads/writes, and (2) Cloud Functions for sensitive actions (approvals, refunds). The roles you define here are written to Firestore so your rules/functions can read and enforce them. MFA and device-fingerprinting are enabled at the Firebase Auth / Identity Platform level, not in this file.Recent Security Events
View full log| Event | User | Detail | Risk | When |
|---|
Roles
Toggle which modules each role can access. Super Admin always has full access (locked). Changes save to the
roles collection for your security rules to enforce.Team Members
| Member | Role | Branch / Warehouse | MFA | Status | Last Active | Actions |
|---|
Session & Access Policies
IP Allowlist
IP restrictions are enforced server-side (Cloud Functions / Identity Platform). Listed here for configuration; they save to
security_policies.Audit Log
| Event | User | Module | Detail | Risk | Timestamp |
|---|