User Role, Permission & Stakeholder Experience Centre
Internal workspace for the BLACKSWAN role taxonomy, permission matrix, segregation-of-duties posture, and the distinct experiences that Founder/Admin, Board, Compliance/Legal, Operations, Evidence Owners, Regulator-review room, Investor-review room, Client/counterparty, Auditor/assurance reviewer, and Technology/Security each see. Every role is bound to the 21-pack evidence spine and the Policy, Procedure & Control Library. Conservative posture: internal readiness only — not legal advice, not regulatory approval, not certification, not audit opinion, not authorization for external launch.
Ten roles · distinct experience · least-privilege default
Founder · Admin · Programme Manager
Sees the full BLACKSWAN OS dock. Dual-sign-off required on Tier-1 changes; founder-root permanence under standing accepted risk (DEC-005) with MFA + re-auth + monthly attestation as compensating controls.
Board · Independent Reviewer
Board-only access to Strategic Reporting board pack, Decision Requests, and standing risk acceptances. Read-only on everything else; never sees raw MNPI or counterparty identifiers.
Head of Regulatory · External Counsel
Counsel countersign authority on regulator-facing language. Reads every regulator-touched pack (Jurisdiction Playbooks, Regulatory Escalation, Model Governance, Reg-Change Horizon). Write-restricted to limitation footers and counsel-locked phrasing.
SRE Lead · Programme Operations
Owns Production Monitoring, Release Control, DR drill, Vendor onboarding runbooks. Approve on Tier-1 release rollback; dual sign-off with CISO on break-glass.
Head of Evidence · Centre Lead
Write authority on assigned evidence packs (1..21); approve authority on pack publish; required attestation per pack on publish; per-file limitation footer enforced (CTL-006).
Regulator-Review (counsel-bounded)
Read-only on counsel-locked, redacted regulator-facing packs only. Never sees Internal Only material. Per-share TTL; per-recipient watermark; audit-logged access.
Investor-Review (redacted variant)
Read-only on counsel-approved, redacted investor narrative (11 sections). No counterparty names; no MNPI; no auditor representation. Per-recipient room link signing.
Client · Counterparty (per-pilot tenant)
Read on per-pilot tenant materials. MNPI binding enforced per share. Onboarding sees KYC partner flow; offboarding rotates all per-recipient signing keys (CTL-003 + CTL-006).
External Auditor · Assurance Reviewer
Read on Financial Controls audit binder · audit-track packs; counsel-bounded scope of work; engagement letter required before any production access; no write authority.
CISO · Identity Lead · Tech Operations
Admin on Auth, Security Operations, Data Governance controls. JIT elevation for break-glass; dual sign-off with COO/CEO on standing privileged actions. Owns access-review cadence and consent records.
Least-privilege default · read-only outside named scope · counsel-bounded externally
| Evidence pack | Founder / Admin | Board | Compliance / Legal | Operations | Evidence Owner | Regulator-Review | Investor-Review | Client / Counterparty | Auditor | Tech / Security |
|---|---|---|---|---|---|---|---|---|---|---|
| Auth | Admin | Read | Read | Read | Write | Deny | Deny | Deny | Read | Admin |
| KYC / KYB Onboarding | Approve | Read | Approve | Read | Write | Read · Redacted | Deny | Read | Read | |
| Data-Room MNPI Access | Admin | Deny | Approve | Deny | JIT | Deny | Deny | Deny | Admin · Dual | |
| Settlement Responsibility | Approve | Read | Approve | Write | Write | Read · Redacted | Deny | Deny | Read | Read |
| Activity Perimeter Decision | Approve | Read | Approve | Read | Write | Read · Counsel-Locked | Read · Redacted | Read · Redacted | Read | Read |
| Control Testing | Approve | Read | Read | Write | Write | Read · Redacted | Deny | Deny | Read | Read |
| Partner-Route Assurance | Approve | Read | Read | Write | Write | Read · Redacted | Deny | Deny | Read | Read |
| Revenue Recognition | Approve | Read | Read | Read | Write | Deny | Read · Redacted | Deny | Read · Engagement | Deny |
| Tax / VAT | Approve | Read | Read | Read | Write | Deny | Deny | Deny | Read · Engagement | Deny |
| Regulatory Digital Twin Decision | Approve | Read | Approve | Read | Write | Read · Counsel-Locked | Deny | Deny | Read | Read |
| Model Risk | Approve | Read | Approve | Read | Write | Read · Counsel-Locked | Read · Redacted | Deny | Read | Read |
| Incident | Approve | Read | Approve | Write | Write | Read · Counsel-Locked | Deny | Deny | Read | Admin |
| Board-Pack Attestation | Approve | Approve · Board-Only | Read | Read | Write | Deny | Deny | Deny | Read | Read |
| Regulatory Change | Approve | Read | Approve | Read | Write | Read · Counsel-Locked | Deny | Deny | Read | Read |
| Complaints | Approve | Read | Approve | Write | Write | Read · Redacted | Deny | Read | Read | |
| Outsourcing Concentration | Approve | Read | Approve | Write | Write | Read · Redacted | Deny | Deny | Read | Read |
| Capital / Liquidity | Approve | Read | Read | Read | Write | Deny | Deny | Deny | Read · Engagement | Deny |
| Policy Attestation | Approve | Read | Approve | Deny | Deny | Read | ||||
| Product Governance | Approve | Read | Approve | Read | Write | Read · Counsel-Locked | Read · Redacted | Read · Redacted | Read | Read |
| Conduct Risk MI | Approve | Read | Approve | Read | Write | Read · Redacted | Deny | Deny | Read | Read |
| Regulatory Exam Response | Approve | Read · Board-Only | Approve · Counsel | Read | Write | Read · Counsel-Locked | Deny | Deny | Deny | Read |
Room class · audience · restriction · counsel countersign · TTL
| Room class | Audience role | Restriction | Counsel countersign | Per-recipient link signing | TTL | Audit-event family |
|---|---|---|---|---|---|---|
| Board room | Board | Board-Only | Where regulator-facing | Required | Per board cycle | BOARD-* |
| Regulator-review room | Regulator-Review | Counsel-locked | Mandatory | Required | Per engagement | REG-* |
| Investor-review room | Investor-Review | Redacted External | Mandatory | Required | 30 d | INV-* |
| Counterparty / pilot room | Client / Counterparty | Per-pilot tenant · MNPI binding | Per-pilot | Required | Per pilot | ROOM-* |
| Auditor / assurance room | Auditor / Assurance | Scope-bound (engagement letter) | Where regulator-touched | Required | Engagement window | AUD-* |
| Internal evidence room | Evidence Owner | Internal Only | n/a (internal) | Optional | Per pack publish cycle | EV-* |
| Compliance/legal review | Compliance / Legal | Counsel-locked | Mandatory | Required | Per submission | COMP-* |
| Tech/Security war-room | Tech / Security | Internal Only · JIT | For regulator-notify | Required | Per incident | SEC-* |
Workflow · accountable · approver · SOD pair · compensating control
| Workflow | Accountable role | Approver role | Required SOD pair | Compensating control | Linked policy / control |
|---|---|---|---|---|---|
| Evidence pack publish | Evidence Owner | Founder/Admin (or Programme) | Author ≠ Approver | Dual sign-off + per-file footer | POL-013 · CTL-004 · CTL-006 |
| Tier-1 release | Operations | Founder/Admin + Tech/Security | Build ≠ Sign-off · SRE ≠ CISO | Dual sign-off + audit log | POL-006 · CTL-004 |
| MNPI room activation | Evidence Owner / Operations | Compliance + Tech/Security | Owner ≠ Approver | Per-share access review + audit log | POL-003 · CTL-003 |
| Regulator-facing artefact | Compliance / Legal | Compliance + Founder | Counsel countersign required | 7-step counsel review workflow | POL-005 · POL-014 · CTL-010 |
| Monthly financial close | Operations / Finance | Founder/Admin (or Board quarterly · Auditor annual) | Booking ≠ Approval · CFO ≠ Auditor | External Auditor + audit binder | POL-008 · POL-017 · CTL-009 |
| Vendor reclassification | Operations | Compliance + Board (material) | Onboarding ≠ Risk classification | Risk Committee minutes + counsel sign-off | POL-007 · POL-016 · CTL-005 |
| Model output override | Evidence Owner / Compliance | Tech/Security + Compliance (dual on regulator-facing) | Build ≠ Override Approval | Override register + counsel countersign | POL-010 · POL-011 · CTL-007 |
| Data deletion / retention hold | Evidence Owner | Tech/Security + Compliance | Custodian ≠ Approver | Hold log + audit-event tag | POL-018 · CTL-006 |
Quarterly cadence · 10 review streams · open exceptions
| Review ID | Role under review | Cadence | Last review | Owner | Outcome / open exception | State |
|---|---|---|---|---|---|---|
| AR-001 | Founder / Admin | Monthly attestation | 2026-05-15 | Board · CISO | Standing risk acceptance (DEC-005) | Live |
| AR-002 | Board | Quarterly | 2026-05-02 | Board Chair | None | Live |
| AR-003 | Compliance / Legal | Quarterly | 2026-05-09 | Compliance · External Counsel | None | Live |
| AR-004 | Operations | Quarterly | 2026-05-08 | Operations · Tech/Security | None | Live |
| AR-005 | Evidence Owner | Quarterly | 2026-05-12 | Evidence Owners · Programme | None | Live |
| AR-006 | Regulator-Review | Per engagement | n/a · counsel-bounded | Compliance · External Counsel | Counsel session 2026-05-19 | Under Review |
| AR-007 | Investor-Review | Per share | n/a · awaiting counsel | Compliance · Founder | Locked until counsel sign-off | Under Review |
| AR-008 | Client / Counterparty | Per pilot | 2026-04-30 | Operations · Compliance | Per-pilot template ready · KYC contract pending | Under Review |
| AR-009 | Auditor / Assurance | Annual + interim | n/a | Operations · Compliance | External auditor engagement letter pending | Stale |
| AR-010 | Break-glass | Quarterly drill | 2026-02-12 | Tech/Security · Operations | Drill overdue (target 2026-05-12) | Break-Glass · Overdue |
Lifecycle steps · consent / attestation · evidence captured
| Step | Onboarding | Offboarding | Owner | Consent / attestation required? | Evidence captured |
|---|---|---|---|---|---|
| 1 · Identity | Microsoft Entra OIDC sign-up (target) · staging factors today | Account disable · token revocation | Tech/Security | Identity attestation | Auth event log · Entra sign-in log |
| 2 · Role assignment | Least-privilege default · named approver per role | Roles removed · approvers re-confirm | Founder/Admin · Tech/Security | Yes · named-approver attestation | RBAC change log |
| 3 · Policy attestation | Sign POL-018 Policy Attestation + role-specific policies | Off-board attestation logged | Compliance · Tech/Security | Yes · annual + role change | Attestation register (POL-018) |
| 4 · Room bindings | Per-room access reviewed and signed | Per-room access removed; per-recipient link signing keys rotated | Operations · Tech/Security | Per-room consent | Room access ledger (ROOM-*) |
| 5 · MNPI binding (where applicable) | MNPI handling attestation · counsel countersign for counterparty/pilot | MNPI binding closed · key rotation | Compliance · Tech/Security | Yes · counsel countersign | MNPI ledger (POL-003) |
| 6 · Training & competency | Security · privacy · MNPI · code of conduct | Last attestation archived | Tech/Security · Compliance | Yes · annual | Training log (TR-EV-ALL-001) |
| 7 · Evidence attestation | Evidence Owner per-pack attestation | Owner re-assigned · attestation re-signed | Programme · Evidence Owner | Yes · per pack | Evidence pack registry |
| 8 · Cadence registration | Added to quarterly access-review stream | Removed from stream · revocation evidence logged | Tech/Security · Programme | n/a | Access review log (AR-*) |
Four gates · all must be green before any external bundle leaves internal scope
Role-bound audience
Recipient role explicitly listed in the permission matrix; least-privilege scope applied; never sees roles outside engagement.
Counsel countersign
External-facing artefact countersigned by external counsel before the per-recipient room link is signed.
Per-recipient watermark & link signing
Every external view has a per-recipient watermark and audit-logged access; no anonymous viewing.
Revocation readiness
Single-action revocation pulls all per-recipient signing keys; offboarding runbook proven on rotation drill.
Audit log of role / permission / access-review events
| Timestamp (UTC) | Actor | Role / Permission / Review | Action | Evidence hash | Limitation recorded | Next step |
|---|---|---|---|---|---|---|
| 2026-05-08 09:00 | CISO · Programme · External Counsel | Role taxonomy (10 roles) | URPS-TAX — taxonomy published | sha256:urps…aa01 | "Internal readiness only." | Quarterly review |
| 2026-05-09 11:14 | CISO · Compliance · Programme | Permission matrix (21 × 10) | URPS-PM — matrix published | sha256:urps…aa02 | "Least-privilege default." | Refresh on pack/role change |
| 2026-05-10 09:22 | Operations · Tech/Security | Stakeholder room access | URPS-SRA — 8 room classes mapped | sha256:urps…aa03 | "Counsel-locked for external." | Per-share counsel sign-off |
| 2026-05-11 14:08 | CISO · Programme · External Counsel | SOD & approvals | URPS-SOD — 8 workflows scoped | sha256:urps…aa04 | "Internal." | Re-test on workflow change |
| 2026-05-12 09:50 | CISO · Operations · Programme | Access reviews | URPS-AR — 10 review streams logged | sha256:urps…aa05 | "Internal." | Close AR-010 break-glass drill |
| 2026-05-13 11:42 | Tech/Security · Programme · Compliance | Onboarding · offboarding | URPS-OO — 8-step lifecycle published | sha256:urps…aa06 | "Internal." | Run drill on next onboarding |
| 2026-05-15 11:30 | External Counsel · CEO · Tech/Security | External visibility gates | URPS-VG — 3 of 4 gates met | sha256:urps…aa07 | "No external bundle without all 4 gates." | Close Gate 2 post 2026-05-19 |
| 2026-05-16 07:55 | CEO · CISO · Compliance | Centre attestation | URPS-ATTESTATION — monthly attestation | sha256:urps…aa08 | "Internal; not regulatory approval." | Re-attest monthly |
What this Centre is — and is not
- Staging / simulated role & permission data. All role IDs, permission entries, access-review records, evidence hashes, dates, and audit events shown here are seed values for an internal readiness workflow. They are not a live IdP, not a live access-review system, and not a live audit log.
- Internal readiness workflow only. This Centre captures BLACKSWAN's internal role & permission posture. It is not legal advice, not regulatory approval, not certification, not an audit opinion, and not authorization for external launch.
- Least-privilege by default. Where a cell is empty or not explicit, the default is Deny. Read-only roles never gain write authority by inference. Approve never implies external sign-off without counsel countersign.
- External roles are counsel-bound. Regulator-Review, Investor-Review, Client/Counterparty, and Auditor experiences require external counsel countersign on the materials they view before any external visibility gate is opened.
- Founder-root is a standing accepted risk. Per Programme Decision Log DEC-005, founder-root permanence carries MFA + re-auth + monthly attestation as compensating controls. AR-001 records the operating consequence.