Organization membership answers where a person may work. Permissions answer what that person may do. GearDock keeps those questions separate so access to a workspace does not silently grant authority to approve, release, export, or administer it.
Organization Membership
A user acts inside an organization workspace selected from verified membership. Products, imports, documents, drafts, reviews, exports, integrations, and audit history are resolved from that server-verified context rather than from an organization identifier supplied by the browser.
Separate Authority
| Activity | What permission means |
|---|---|
| Prepare catalog work | Import data, attach sources, resolve matches, and prepare governed drafts. |
| Review and approve | Inspect evidence and record a decision on a specific content version. |
| Release | Make an approved version eligible to leave GearDock; approval alone is insufficient. |
| Export or synchronize | Send currently released content to an authorized destination within the organization scope. |
| Administer | Manage approved workspace configuration, membership, and connected-system settings. |
Generation Carries No Authority
Audit and Accountability
Important decisions preserve the acting identity, organization, affected record and version, action, outcome, and time. Corrections are appended as new events; historical governance records are not rewritten or deleted.
Least-Privilege Onboarding
- List the work each team must perform.
- Grant only the corresponding organization and action permissions.
- Separate approval, release, export, and administration where the operating model requires it.
- Review membership and connected-system access when responsibilities change.