ap user
Standard accessap_user has no sensitive capabilities.
3 total | 0 sensitive
ap.managecash_forecast.manageledger.read
Controls
Baseline ERP-owned capability model for finance roles. Owner-only user management and auth-provider wiring can build on this matrix without changing the control vocabulary.
ap_user has no sensitive capabilities.
ar_user has no sensitive capabilities.
external_finance_admin has 6 sensitive capabilities.
finance_admin has 6 sensitive capabilities.
owner has 7 sensitive capabilities.
read_only_consultant has no sensitive capabilities.
External finance admins intentionally have broad accounting access in V1, but `users.manage` remains owner-only. Sensitive reads and self-approvals are visible in the audit trail for periodic review.