Authorization model, role-based access control, and security analysis.
Who can do what in setldhub — the role and permission model
Who can act for whom — effective client scope, the single acting client for changes, and the isolation guardrails