Skip to content
GearDock

Documentation

Roles and Permissions

How organization membership and separate operational permissions preserve human authority across review, release, export, and administration.

Last updated

Organization membership answers where a person may work. Permissions answer what that person may do. GearDock keeps those questions separate so access to a workspace does not silently grant authority to approve, release, export, or administer it.

Organization Membership

A user acts inside an organization workspace selected from verified membership. Products, imports, documents, drafts, reviews, exports, integrations, and audit history are resolved from that server-verified context rather than from an organization identifier supplied by the browser.

Separate Authority

Operational authority remains explicit
ActivityWhat permission means
Prepare catalog workImport data, attach sources, resolve matches, and prepare governed drafts.
Review and approveInspect evidence and record a decision on a specific content version.
ReleaseMake an approved version eligible to leave GearDock; approval alone is insufficient.
Export or synchronizeSend currently released content to an authorized destination within the organization scope.
AdministerManage approved workspace configuration, membership, and connected-system settings.

Generation Carries No Authority

A generated draft cannot approve or release itself. Integration execution also carries no independent authority: it must re-check the current product, release, permission, and destination state.

Audit and Accountability

Important decisions preserve the acting identity, organization, affected record and version, action, outcome, and time. Corrections are appended as new events; historical governance records are not rewritten or deleted.

Least-Privilege Onboarding

  1. List the work each team must perform.
  2. Grant only the corresponding organization and action permissions.
  3. Separate approval, release, export, and administration where the operating model requires it.
  4. Review membership and connected-system access when responsibilities change.

Something here unclear or out of date? Tell us Documentation gaps are worth more to us than feature requests.