Protected programme
Founding Partners
A distinct protected environment with its own namespace, its own audience and its own data scope. It is not a tier of the client portal, and it is not part of the internal environment.
ProtectedNot available in this phase. Authentication, sessions and the environment itself are later phases — nothing on this page grants access or simulates it.
Scope
What this environment is, and how it is separated from every other part of the group.
- Founding Partner membership is an explicit entitlement issued by MAP Holding. It is never inferred from a principal kind.
- Being a client does not make anyone a founding partner. Being a MAP Holding employee does not either. Both require a separate, auditable grant.
- The entitlement is additive only: it never raises a principal's clearance ceiling, so it cannot expose internal or confidential material.
- Programme content is unreachable without the entitlement, even by the principal that owns the record.
- Because it is a namespace rather than a role, the programme can be opened, paused or closed without disturbing client access.
What authorization decides
Enforced at the data and API layer, never by hiding interface elements.
Must never be reachable
- Programme material belonging to another partner
- Internal MAP Holding assessments of the programme
- Confidential group reports and financials
- Any client's records — the two environments do not overlap
Authorization model
This matrix is generated from the shipped access-control contract, not typed by hand. If a clearance ceiling ever changes, this table changes with it.
| Visibility class | anonymousoutside | clientoutside | partneroutside | staffinside | admininside | ownerinside |
|---|---|---|---|---|---|---|
| public | reachable | reachable | reachable | reachable | reachable | reachable |
| client | not reachable | reachable | reachable | reachable | reachable | reachable |
| partner | not reachable | not reachable | reachable | reachable | reachable | reachable |
| internalnever client-reachable | not reachable | not reachable | not reachable | reachable | reachable | reachable |
| adminnever client-reachable | not reachable | not reachable | not reachable | not reachable | reachable | reachable |
| confidentialnever client-reachable | not reachable | not reachable | not reachable | not reachable | not reachable | reachable |
- public
- Published to the open web. No principal required.
- client
- Belongs to one client account. Visible only to that client.
- partner
- Shared under a partnership relationship, not with clients.
- internal
- MAP Holding personnel only. Never client-reachable.
- admin
- Administrative and operational control data. Never client-reachable.
- confidential
- Highest restriction: board, financial and strategy material.
PlaceholderRequired before this environment can be built
Nothing here is simulated. These are the real prerequisites.
- Programme definition and eligibility criteria
- Entitlement grant and revocation workflow
- Programme documents and communications
- Programme-specific reporting
- Separate gated shell and navigation
- Authentication provider and session model
Full architecture: docs/ACCESS-CONTROL-ARCHITECTURE.md
