Skip to content
CortexDocs
Budget Control · Permissions

Visibility and permissions

Current Cortex roles and visibility, with scoped budget-manager authority explicitly proposed.

Current roles and visibility

Cortex documents two roles, Member and Admin, and three independent visibility settings, Self, Team, and Organization. Admin controls administrative actions; visibility controls whose synced data is included. An Admin can have Self visibility.

Team visibility uses active shared Team membership. Department membership does not grant visibility, and a reporting relationship does not grant budget-edit permission. Organization-wide data appears on pages that support that scope. Consult Roles and visibility for the current contract.

Proposed budget-manager authority

The proposed enterprise contract delegates authority to named budget managers over explicit scopes. Define separate rights to view Estimated spend, inspect captured evidence, edit limits, change policy, assign ownership, and authorize exceptions. Do not make every manager an unrestricted organization administrator.

A subtree shown in Org chart is a proposed management context, not an implemented authorization rule. Backend enforcement must validate both read and write scope server-side. Acceptance must include a manager allowed within the assigned scope and denied when reading or changing another scope.

Self-approval restrictions, manager substitution, and transfer of ownership require explicit rules. None are inferred from chart position. Developers' Atlas access remains governed by their assigned role and visibility; it is not universally disabled by this proposal.

Target contract

The following describes planned enterprise behavior. Current behavior remains defined above.

Proposed delegated authority

A future budget-manager role would grant explicit read and write rights over named scopes alongside the existing Member/Admin roles. It would need server-side checks, substitution, transfer and self-approval rules.

Permission to inspect captured evidence would remain separate from permission to change limits. A chart node, reporting title or funding relationship would not by itself grant either permission.

Was this helpful?