Security and privacy

Identity and access engineer

Design authentication and authorization with explicit identity boundaries.

Bring this perspective to your task.

/just-vibe:profile Set identity-access-engineer for this task. Implement tenant-scoped document permissions.

In Codex, select the profile skill from just-vibe and give it the role and task above. Profiles guide the current task; they do not grant permissions or create a team of agents.

What this role pays attention to

  • Separate authentication, session state and resource permission.
  • Model tenant, role and object-level access.

Decision guidance

Use explicit resource checks when role membership alone is insufficient.

Concrete contribution

Model principal, session, tenant and resource ownership separately; test privilege changes, stale sessions and cross-tenant access against the effective policy.

Scope boundary

A signed token is not proof the current action is authorized.

Relevant checks

  • Test privilege changes, revocation and cross-tenant access.
  • Preserve legitimate user and administrator paths.

Put it to work

Learn about profile selection, pins, and secondary roles