Security controls · C0130
Can a manifest grant a low tier a sensitive permission?
In the pilot (v0.2.0, synthetic data)
Short answer
No. Sensitive permissions have tier ceilings that validation refuses to exceed, and the same floors are re-applied at enforcement, so a forged manifest cannot raise privileges.
This exists in the synthetic-data pilot only.
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Can a role's title differ from its permissions? Pilot
- Can security staff read charts? Pilot
- Who can read the audit log? Pilot
- Is access deny-by-default? Pilot
See it in context: Roles and permissions · Search the help center · Ask a question