9 roles, org + workspace
Owner, admin, billing, researcher, enumerator, analyst, respondent-manager, auditor, viewer. Least-privilege by default.
- Org-level + workspace-level scopes
- Role matrix exportable for audit
- Session + MFA policies per role
- Service accounts with rotating keys