How access works
- A member belongs to one tenant with one role.
- A role holds scopes from a fixed catalog. Each scope has a
readand awritetier, andwritealways includesread. - The reserved admin role bypasses every scope check inside its tenant. It is created with the tenant and cannot be edited.
- Frayme operators are super-admins. They can act across tenants and see the Admin group in the sidebar.
- Role names are lowercase letters and hyphens, for example
senior-analyst.
The scope catalog
Two gates surprise people. Editing Decline Reasons and Tags in Settings needs
risk:write, not cases:write. Managing the AI provider key needs datasources:write.Recommended role templates
queues:read and communications:read are on the engineer template because the Review node’s queue picker and the Send RFI node’s template picker read those lists. cases:write is there because Submit case in the builder creates a case, which means an engineer can also decide cases; drop it if that is not acceptable and have a manager run the test submissions. team:read lets analysts and engineers open Team read-only.
What each template sees
Every Settings tab is rendered for every member. “view” means the tab opens but its controls are read-only or are rejected with a permission error when used; the Queues and API tabs still show their Create buttons to everyone.
Opening a page your role cannot see shows an access-denied panel rather than an empty page.