---
phase: permissions
kind: level
level: discovery
---

# Phase 1: DISCOVERY — broad-stroke access per module

> Follow this file when the decision table in `SKILL.md` routes here. The action
> vocabulary, scopes and authority rules live in `SKILL.md`.

## Goal

Establish broad-stroke access: which actors can reach module M in app X, at the
module level (`module.access` / `module.read`), before refining per section.

## Before proposing — read the tree

1. `Glob .smartstack/ba/**/index.md` — list every module in app X.
2. Read `<APP>/acteur.md` — the actors with their `BA-…-AC-…` codes and types
   (`internal` / `external` / `system`). Grep a code to confirm it exists.
3. Read `<APP>/<MODULE>/use-case.md` (+ each section's `use-case.md`) — identify
   the primary/secondary actors per module.
4. Read the module's existing `rbac.md` — anything already defined?

## UC cross-reference — infer minimum access

For module M, scan its use cases. Every UC's **primary actor** must get at least
`access` + `read` on M. In your prose, justify each line with the UC code that
implies it. Actors not referenced by any UC for M may still be proposed from
their type:

- `internal` admin-type actors → `access` + `read` on the module (often broader).
- `external` actors → `access` only, usually at application level (their portal).
- `system` actors → `access` + `read` + `execute` on the relevant modules.

## Propose — one AskUserQuestion per module

Describe the candidates in prose, then ask via **AskUserQuestion** (one
multi-select per module) which actors should access the module. Pre-select the
actors inferred from use cases and note the justification next to each. Open
exploration questions (cross-region isolation, who owns approvals) go in prose,
not in the closed choice.

## After the user validates → Write the matrix

1. Acknowledge briefly (one sentence).
2. **Write** `<APP>/<MODULE>/rbac.md` with the module-level lines, re-listing
   every line that must survive (the Write overwrites the file). Use the
   `rbac.md` skeleton from `SKILL.md`: module-level permissions `module.action`
   (e.g. `pipeline.access`, `pipeline.read`), scope in the Portée column.
   Section-level permissions add the section segment in Phase 2.
3. Announce the next module, or the transition to Phase 2 (detail) for this
   module's sections.

Module-level discovery lines look like `module.access` and `module.read` (no
section segment yet). Phase 2 adds the section segment and the specific actions.

> A module-level line is a **GRANT**, not a permission declaration: the
> `{app}.{module}.access` permission ROW exists by construction (the permission
> floor — see SKILL.md § "Permission floor"), and Phase 0 transports your
> module-grain grant lines onto it (they are no longer dropped).

## Transition (Phase 1 → Phase 2)

When module M has broad-stroke access for every validated actor, move to Phase 2
for M's sections (follow `levels/detail.md`). When every module in app X has
broad-stroke access, Phase 1 is complete for X.
