diff --git a/src/utils/AGENTS.md b/src/utils/AGENTS.md index 8d48d12..a2f2f34 100644 --- a/src/utils/AGENTS.md +++ b/src/utils/AGENTS.md @@ -26,7 +26,10 @@ Full RBAC check against `src/permissions/index.ts` (100+ permissions). Superuser Lightweight role checks. Used for quick conditional rendering (e.g., `isRole("admin")` for admin-only UI). No Payload call — reads from the user object directly. ### 3. `hasLogisticsQualification()` / `hasIntelligenceQualification()` -Queries `Profiles.progression.qualifications` for specific qualification strings (case-insensitive). Admin/developer always pass. Used to gate logistics-only and intelligence-only UI sections. +Queries `Profiles.progression.qualifications` for specific qualification strings (case-insensitive), with domain write permissions as a pass. Admin/developer always pass. Used to gate moderation and management surfaces (wiki moderation, tech tree editing, division admin pages, logistics-only UI). + +### 4. `canViewIntelligence()` +Read-permission visibility check (`missions:read` / `campaigns:read` / `factions:read` / `technologies:read`, all granted by the standard user role) with the strict intelligence qualification as fallback. Gates the Intelligence sidebar section, command palette, keyboard shortcuts, dashboard widgets, and tour visibility. Never use it for moderation decisions; use `hasIntelligenceQualification()` for those. ### Permission tiers and admin panel gates - `system:admin-access` (registry label "Superuser Tier (user management, notification oversight, final approval states)") is the functional superuser tier: final approval states (`approvalStatusFieldAccess` in `divisionAccess.ts`), the Users admin page, read-all notifications. Held ONLY by the built-in `admin` role and superuser roles. NEVER grant it to division roles; a hand grant once made officers approval-superusers.