Protected environment · personnel
Internal Environment
The environment MAP Holding personnel use. It is a separate product from the Client Portal, not a set of extra menus inside it, and it is not reachable from a client account.
ProtectedNot available in this phase. Authentication, sessions and the environment itself are later phases — nothing on this page grants access or simulates it.
Scope
What this environment is, and how it is separated from every other part of the group.
- A client principal's clearance ceiling is exactly `client`, so internal, admin and confidential resources are unreachable by a client however ownership or grants are arranged.
- Internal reports, assessments, financial information and strategy are structurally excluded from the client portal, not merely hidden in its interface.
- An internal user is never a client portal destination: the two environments share the brand foundation and nothing else.
- Becoming a client does not grant internal access, and internal access does not grant founding-partner membership.
- Every read is decided server-side by the same authorization contract used across the group.
What authorization decides
Enforced at the data and API layer, never by hiding interface elements.
Must never be reachable
- Client accounts and client records
- Client documents and messages
- Internal material surfaced into any client-facing surface
Authorization model
This matrix is generated from the shipped access-control contract, not typed by hand. If a clearance ceiling ever changes, this table changes with it.
| Visibility class | anonymousoutside | clientoutside | partneroutside | staffinside | admininside | ownerinside |
|---|---|---|---|---|---|---|
| public | reachable | reachable | reachable | reachable | reachable | reachable |
| client | not reachable | reachable | reachable | reachable | reachable | reachable |
| partner | not reachable | not reachable | reachable | reachable | reachable | reachable |
| internalnever client-reachable | not reachable | not reachable | not reachable | reachable | reachable | reachable |
| adminnever client-reachable | not reachable | not reachable | not reachable | not reachable | reachable | reachable |
| confidentialnever client-reachable | not reachable | not reachable | not reachable | not reachable | not reachable | reachable |
- public
- Published to the open web. No principal required.
- client
- Belongs to one client account. Visible only to that client.
- partner
- Shared under a partnership relationship, not with clients.
- internal
- MAP Holding personnel only. Never client-reachable.
- admin
- Administrative and operational control data. Never client-reachable.
- confidential
- Highest restriction: board, financial and strategy material.
PlaceholderRequired before this environment can be built
Nothing here is simulated. These are the real prerequisites.
- Authentication provider and session model
- Internal-only navigation and shell
- Internal reporting and assessment tooling
- Audit logging for access decisions
- Role and entitlement administration
Full architecture: docs/ACCESS-CONTROL-ARCHITECTURE.md
