Combine roles and entitlements
Last updated:
Framework roles answer whether the current membership may perform an organization-governance operation. Entitlements answer whether the organization currently has access to a product capability.
Warning
WS-005 authorization and WS-006 entitlement implementation are not ready. This page defines the accepted composition boundary.
Separate decisions
A role decision must not infer subscription or plan access. An entitlement decision must not infer membership administration authority.
A protected paid operation generally requires:
- authenticated account;
- validated organization context;
- an allowed organization or consumer policy;
- an allowed entitlement decision;
- operation-specific target and version invariants.
Each stage can deny independently and should produce a bounded safe result.
Billing policies
Billing.View and Billing.Manage are framework role policies. They govern who may inspect or administer normalized billing state; they do not prove that a plan or entitlement is active.
Request-time boundary
Protected request authorization uses authoritative local organization and entitlement state. It must not call Stripe or another provider synchronously to decide access.
Consumer composition
A consumer policy may require a framework policy, explicit framework roles, a product-specific requirement, and a consumer entitlement check. It cannot weaken the framework policy or replace the provider-neutral entitlement evaluator.