RBAC by permission
Super Admin, Catalog, Operations and the other roles are default bundles only; real authority is permission-based, not hard-coded to role names.
Staff need an immediate view of what requires action now: orders, delivery capacity, Character capacity, low stock, payment issues, imports and upcoming risks — with auditability and permissions around sensitive actions.
This simulation is not presented as final Admin UI. It demonstrates how the Kidzy team should experience the system: scan-friendly information, clear decisions, and visible impact before confirming sensitive actions.
Every capability must travel through the full chain: customer surface → domain/API → persistence → Admin control → audit/report.
| Feature | Customer | Domain / API | Database | Admin | Audit / Report |
|---|
Super Admin, Catalog, Operations and the other roles are default bundles only; real authority is permission-based, not hard-coded to role names.
Wallet adjustment, refund, stock adjustment, price modification or forced capacity override requires permission + reason + actor + timestamp.
Closing a period with confirmed orders or reducing capacity below confirmed quantity must show impact and prevent an invalid state.