Role Set Admin Preview
Purpose
This preview shows how Renata may eventually define reusable role-set templates for a deployment before any user admin, role admin CRUD, permission change, identity storage, or configuration write exists.
It is not live role management. It is static planning metadata for staff/privacy review.
What A Role Set Is
A role set is a planned bundle of roles and permission boundaries for a Renata deployment. In a future approved version, a role set could define who can view packets, view protected previews, draft future workflow items, or review future drafts.
In this phase, role sets are preview-only. No lifecycle state triggers behavior.
Default Renata Role Set
Default Renata role set
preview-onlyResident
resident
Future participant role for approved community workflows after identity and privacy policy approval.
Peer Leader
peer-leader
Future peer support role that may help identify drafts but cannot approve public reading.
Staff Reviewer
staff-reviewer
Future protected review role for staff-approved workflow checks after role policy approval.
Program Admin
program-admin
Future configuration role for approved staff operators after account, audit, and privacy gates.
Future Permission Map
Packet viewing
- View Daily Packet
active-read-onlyRead-only public/source-backed packet view.
- View Presenter Script
active-read-onlyRead-only presenter script generated from packet data.
- View Operator Summary
active-read-onlyRead-only packet diagnostics; not staff admin.
Protected preview viewing
- View Protected Previews
active-read-onlyProtected read-only planning surfaces only.
Drafting future submissions
- Draft Pull-Up
blocked-before-liveNo live pull-up drafts exist until account, identity, review, retention, and privacy gates are approved.
- Draft Push-Up
blocked-before-liveNo live push-up drafts exist until account, identity, review, retention, and privacy gates are approved.
Staff review future permissions
- Review Drafts
blocked-before-liveFuture staff review is blocked until role, privacy, retention, and audit policy are approved.
Morning Sheet future permissions
- Approve For Morning Sheet
blocked-before-liveNo resident or peer-leader role may finalize public Morning Sheet placement.
Admin configuration future permissions
- Manage Role Sets
requires-staff-approvalNo role admin CRUD or configuration writes exist.
- Manage Workflow Sets
requires-staff-approvalNo workflow admin CRUD or configuration writes exist.
Retention/audit future permissions
- Manage Retention Policy
requires-privacy-approvalRetention policy is planning-only and cannot be changed by the app.
Future Role-Set Templates
Small Sober Living
A compact residential recovery setting that needs read-only packet access and future staff-reviewed accountability workflows.
- ID
- small-sober-living
- Status
- preview-only
Roles: resident, peer-leader, staff-reviewer, program-admin
Included permissions: view_daily_packet, view_presenter_script, view_protected_previews
Excluded permissions: approve_for_morning_sheet, manage_role_sets, manage_retention_policy, view_identity_data
Preview-only template. Future pull-up/push-up drafting and review permissions remain blocked until staff/privacy approval.
Clinical Program Lite
A treatment-program planning shape that keeps Renata non-clinical while modeling stricter staff review boundaries.
- ID
- clinical-program-lite
- Status
- preview-only
Roles: resident, staff-reviewer, program-admin
Included permissions: view_daily_packet, view_presenter_script, view_operator_summary, view_protected_previews
Excluded permissions: draft_pullup, draft_pushup, approve_for_morning_sheet, enable_ai_for_real_submissions
Preview-only template. It makes no clinical claims and does not activate resident workflows.
Peer-Led Community
A recovery community planning shape where peer leaders may eventually help route drafts but cannot finalize public display.
- ID
- peer-led-community
- Status
- preview-only
Roles: resident, peer-leader, staff-reviewer
Included permissions: view_daily_packet, view_presenter_script, view_protected_previews
Excluded permissions: review_drafts, approve_for_morning_sheet, manage_workflow_sets, export_records
Preview-only template. Peer leaders cannot finalize staff review or approve Morning Sheet placement.
Private Coaching Cohort
A small coaching-oriented planning shape for structured orientation without community accountability submissions.
- ID
- private-coaching-cohort
- Status
- preview-only
Roles: resident, program-admin
Included permissions: view_daily_packet, view_presenter_script
Excluded permissions: draft_pullup, draft_pushup, review_drafts, view_identity_data, manage_retention_policy
Preview-only template. It does not include live submissions, resident profiles, identity records, or coaching-client data.
Future Role-Set Lifecycle
| Lifecycle state | Preview behavior |
|---|---|
| Template template | Static planning example only. |
| Draft Configuration draft-configuration | Future planning state only; no edits are saved. |
| Staff Review Required staff-review-required | Future review gate label only. |
| Privacy Review Required privacy-review-required | Future privacy gate label only. |
| Pilot Ready pilot-ready | Future state label only; cannot launch behavior in this phase. |
| Active active | Listed as a possible future lifecycle state; no role set can be active in this preview. |
| Archived archived | Future historical state label only; no records are stored. |
All role sets in this phase are preview-only. None are active, and no lifecycle state can trigger behavior.
What Role Admin May Eventually Configure
- Role labels and descriptions after staff/privacy review.
- Permission mappings for approved role sets after policy approval.
- Role-set templates for approved deployment contexts.
- Lifecycle labels for future review gates, without bypassing staff or privacy approval.
What Remains Blocked
Safety And Privacy Boundaries
| Blocked permission | Status | Reason |
|---|---|---|
| Assign real users assign_real_users | blocked-before-live | User assignment requires identity policy, account model, privacy approval, and audit logging. |
| Approve submissions approve_submissions | blocked-before-live | Submission approval requires staff review policy and live workflow approval. |
| Delete submissions delete_submissions | blocked-before-live | Deletion requires retention and audit policy before any live storage exists. |
| Export records export_records | blocked-before-live | Exports require staff/privacy approval and a data-minimization policy. |
| Change retention policy change_retention_policy | blocked-before-live | Retention policy changes require privacy approval and audit design. |
| Enable AI for real submissions enable_ai_for_real_submissions | blocked-before-live | AI use for real community submissions requires separate staff/privacy approval. |
| View identity data view_identity_data | blocked-before-live | Identity data viewing is blocked because no identity storage exists. |
Future Validation Rules
- Every role set must include at least one staff-review role before live submissions.
- No resident role may approve public Morning Sheet placement.
- No peer-leader role may finalize staff review.
- Export permissions require staff/privacy approval.
- AI permissions require separate AI-use approval.
- User assignment requires identity policy approval.
- No attendance or participation tracking permissions exist.
- No scoring/ranking/compliance permissions exist.
Recommended Next Phase
Phase 7.5 - Config-Only Role Set CRUD Design, Planning Only
Phase 7.4 now adds the Admin CRUD Readiness Review. The next planning step is role-set template CRUD design only, without implementation, migrations, writes, user assignment, identity capture, submissions, or live workflow activation.
planning-only