Accounts, roles and privileges
Everyone sees what concerns them: rights are granted screen by screen, not in bulk.
Giving someone access should not mean giving them everything. In Aurora an account carries a role and a list of privileges, and the side menu shows only what is open to it.
What can be set
- Privileges per screen and per action: view, create, edit, delete.
- An email invitation, with the account created disabled if needed.
- Email verification and password reset.
- An audit log: who changed what, and when.
- The ability to stand in an account to check what it sees.
So a client can write without touching the settings, and their intern can write without being able to publish.