refactor: centralize runtime RBAC policy #33
Reference in New Issue
Block a user
Delete Branch "fix/rbac-policy-ssot"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Why
The runtime had two copies of the RBAC role table. That can drift and produce inconsistent behavior between MCP tool gates and built-in audit/governance paths.
Verification
Tier
Tier 2 — runtime authorization policy refactor with regression coverage.
Approved: RBAC policy is centralized in runtime SSOT with focused regression coverage and green CI.
Approved: RBAC policy is centralized in runtime SSOT with focused regression coverage and green CI.