Authorization & Security Matrix
GN-Apex enforces a zero-trust, multi-dimensional security model. Access is strictly partitioned across three distinct layers: the global platform portal, the corporate organization, and the individual project nodes.
“Ensure absolute security isolation. Developers access isolated code environments, while executives control corporate billing, and editors manage scoped project content.”
Tri-Layer Authorization Matrix
To support everything from solo founders to massive digital agencies, permissions are evaluated progressively top-down. Users are first routed to their designated platform portal, granted baseline corporate rights, and finally assigned strict operational clearance on a per-project basis.
Layer 1: Platform Level (Portals)
When an account is created on GN-Apex, it is permanently assigned a core platform identity. This dictates which ecosystem portal they log into.
The Client Dashboard
Accessed by business owners, marketing teams, and agency managers. This portal provides full visibility into CRM, billing, content, and analytics.
The Developer Portal
Accessed by verified engineers and freelancers. Provides a specialized terminal to view assigned project scopes, manage codebase assignments, and process earnings payouts.
Layer 2: Organization Level
Inside the Client Dashboard, users belong to one or more Organizations. Organization-level roles dictate global administrative privileges—like managing credit cards, purchasing domains, or creating entirely new projects.
Organization Owner
Absolute root authority. The only role with authority to update the global permission matrix, delete the organization, or modify KYC/KYB legal DNA.
Organization Admin
Operational leadership. Can provision new projects, invite and remove team members, configure storage nodes (BYOS), and top-up Resource Vaults.
Billing Manager
Fiscal officer. Manages invoices, bank cards, mobile money payment methods, subscription plans, and wallet transactions without touching website content.
Content Editor
Creative specialist. Manages content schemas, drafts articles, uploads media assets, and reviews translations across all organization projects.
Organization Capabilities Breakdown
| Governance Action | Owner | Admin | Billing Manager | Content Editor |
|---|---|---|---|---|
| Modify Legal DNA & KYC/KYB | ✓ | — | — | — |
| Sync Master Permission Matrix | ✓ | — | — | — |
| Provision & Delete Projects | ✓ | ✓ | — | — |
| Invite & Remove Teammates | ✓ | ✓ | — | — |
| Manage Wallets & Invoices | ✓ | ✓ | ✓ | — |
| Configure Storage Nodes (BYOS) | ✓ | ✓ | — | — |
| Edit Schemas & Media Library | ✓ | ✓ | — | ✓ |
Layer 3: Project Node Level
Because an agency might manage 50 different projects within one Organization, GN-Apex isolates access on a per-project basis. A user might be the lead Admin on Project Alpha, but have absolutely zero visibility into Project Beta.
Project Admin
Full control over the specific project node. Can trigger edge deployments, rotate cryptographic API keys, and manage localized team access.
Contributor
The daily operator. Can edit and publish CMS content, upload media, reply to WhatsApp/Email inbox threads, and manage products or events.
Viewer
Auditor access. Can inspect analytics telemetry, read content drafts, and view support tickets, but cannot execute any write or publish actions.
Restricted
Completely severed access. Preserves the user's historical audit logs and assignment records while instantly halting their login capabilities.
Granular Permission Scopes
Beyond standard roles, GN-Apex evaluates strict, granular scope strings before fulfilling any sensitive request. Organization Owners can build custom roles by toggling these exact capabilities on or off:
| Parameter | Type | Requirement | Description |
|---|---|---|---|
| project.settings.update | Infrastructure | Optional | Modify project brand colors, metadata, logos, and operational workspace modes. |
| content.publish | Content Engine | Optional | Promote draft schemas and trigger global Next.js ISR and Cloudflare CDN cache purges. |
| content.media.upload | Media Vault | Optional | Upload assets to the media storage cluster and trigger automated WebP/H.264 optimization. |
| deploy.trigger | CI/CD & DevOps | Optional | Trigger production builds and deployments to Cloudflare Pages via GitHub Actions. |
| inbox.write | Communications | Optional | Send outbound replies to customers over WhatsApp, SMS, and custom-domain Email. |
| treasury.allocation | Billing Faucets | Optional | Adjust project-level monthly limits for SMS, WhatsApp, and AI token resource consumption. |
| seo.audit | Intelligence | Optional | Run automated Lighthouse technical audits and query Google Search Console keyword rankings. |
| audit.logs.export | Forensics | Optional | Filter, inspect, and export immutable regulatory audit logs across team operations. |
Severance & Restricted Mode
If an employee leaves the company or a contractor concludes their milestone, an Admin must revoke their access. Deleting a user profile outright destroys the historical audit trail (e.g., "Who published this page last month?").