← BLACKSWAN OS
User Role · Permission · Stakeholder Experience
Internal Readiness · Simulated
Centre Status

User Role, Permission & Stakeholder Experience Centre

Internal workspace for the BLACKSWAN role taxonomy, permission matrix, segregation-of-duties posture, and the distinct experiences that Founder/Admin, Board, Compliance/Legal, Operations, Evidence Owners, Regulator-review room, Investor-review room, Client/counterparty, Auditor/assurance reviewer, and Technology/Security each see. Every role is bound to the 21-pack evidence spine and the Policy, Procedure & Control Library. Conservative posture: internal readiness only — not legal advice, not regulatory approval, not certification, not audit opinion, not authorization for external launch.

Roles catalogued
10
Founder/Admin · Board · Compliance · Operations · Evidence Owner · Regulator-review · Investor-review · Client · Auditor · Tech/Security
Permission rules
21 × 10
21 evidence packs × 10 roles · least-privilege default
Access reviews
10
Quarterly cadence · 1 stale · 1 break-glass overdue
Open exceptions
8
Risk-committee or counsel-bound
Permission action legend
Read Write Approve Admin · Dual Deny JIT · Time-boxed Consent · Attestation Required Live Under Review Stale · Review Overdue Break-Glass
Role taxonomy & stakeholder experience

Ten roles · distinct experience · least-privilege default

Posture: permissions describe internal staging readiness only. They do not constitute role-based access for any external/regulator/counterparty system. Counsel countersign required on every regulator-facing or investor-facing experience before any external use.
Role 1 · Founder / Admin

Founder · Admin · Programme Manager

Sees the full BLACKSWAN OS dock. Dual-sign-off required on Tier-1 changes; founder-root permanence under standing accepted risk (DEC-005) with MFA + re-auth + monthly attestation as compensating controls.

Admin · Dual
Role 2 · Board

Board · Independent Reviewer

Board-only access to Strategic Reporting board pack, Decision Requests, and standing risk acceptances. Read-only on everything else; never sees raw MNPI or counterparty identifiers.

Approve · Board-Only
Role 3 · Compliance / Legal

Head of Regulatory · External Counsel

Counsel countersign authority on regulator-facing language. Reads every regulator-touched pack (Jurisdiction Playbooks, Regulatory Escalation, Model Governance, Reg-Change Horizon). Write-restricted to limitation footers and counsel-locked phrasing.

Counsel Countersign
Role 4 · Operations

SRE Lead · Programme Operations

Owns Production Monitoring, Release Control, DR drill, Vendor onboarding runbooks. Approve on Tier-1 release rollback; dual sign-off with CISO on break-glass.

Approve · Dual on Tier-1
Role 5 · Evidence Owner

Head of Evidence · Centre Lead

Write authority on assigned evidence packs (1..21); approve authority on pack publish; required attestation per pack on publish; per-file limitation footer enforced (CTL-006).

Write · Pack Owner
Role 6 · Regulator-Review Room

Regulator-Review (counsel-bounded)

Read-only on counsel-locked, redacted regulator-facing packs only. Never sees Internal Only material. Per-share TTL; per-recipient watermark; audit-logged access.

Read · Counsel-Locked
Role 7 · Investor-Review Room

Investor-Review (redacted variant)

Read-only on counsel-approved, redacted investor narrative (11 sections). No counterparty names; no MNPI; no auditor representation. Per-recipient room link signing.

Read · Redacted
Role 8 · Client / Counterparty

Client · Counterparty (per-pilot tenant)

Read on per-pilot tenant materials. MNPI binding enforced per share. Onboarding sees KYC partner flow; offboarding rotates all per-recipient signing keys (CTL-003 + CTL-006).

Consent · MNPI Binding
Role 9 · Auditor / Assurance

External Auditor · Assurance Reviewer

Read on Financial Controls audit binder · audit-track packs; counsel-bounded scope of work; engagement letter required before any production access; no write authority.

Read · Scope-Bound
Role 10 · Technology / Security

CISO · Identity Lead · Tech Operations

Admin on Auth, Security Operations, Data Governance controls. JIT elevation for break-glass; dual sign-off with COO/CEO on standing privileged actions. Owns access-review cadence and consent records.

Admin · JIT
Permission matrix · 21 evidence packs × 10 roles

Least-privilege default · read-only outside named scope · counsel-bounded externally

Evidence pack Founder / Admin Board Compliance / Legal Operations Evidence Owner Regulator-Review Investor-Review Client / Counterparty Auditor Tech / Security
AuthAdminReadReadReadWriteDenyDenyDenyReadAdmin
KYC / KYB OnboardingApproveReadApproveReadWriteRead · RedactedDenyConsentReadRead
Data-Room MNPI AccessAdminDenyApproveDenyJITDenyDenyConsent · per-pilotDenyAdmin · Dual
Settlement ResponsibilityApproveReadApproveWriteWriteRead · RedactedDenyDenyReadRead
Activity Perimeter DecisionApproveReadApproveReadWriteRead · Counsel-LockedRead · RedactedRead · RedactedReadRead
Control TestingApproveReadReadWriteWriteRead · RedactedDenyDenyReadRead
Partner-Route AssuranceApproveReadReadWriteWriteRead · RedactedDenyDenyReadRead
Revenue RecognitionApproveReadReadReadWriteDenyRead · RedactedDenyRead · EngagementDeny
Tax / VATApproveReadReadReadWriteDenyDenyDenyRead · EngagementDeny
Regulatory Digital Twin DecisionApproveReadApproveReadWriteRead · Counsel-LockedDenyDenyReadRead
Model RiskApproveReadApproveReadWriteRead · Counsel-LockedRead · RedactedDenyReadRead
IncidentApproveReadApproveWriteWriteRead · Counsel-LockedDenyDenyReadAdmin
Board-Pack AttestationApproveApprove · Board-OnlyReadReadWriteDenyDenyDenyReadRead
Regulatory ChangeApproveReadApproveReadWriteRead · Counsel-LockedDenyDenyReadRead
ComplaintsApproveReadApproveWriteWriteRead · RedactedDenyConsentReadRead
Outsourcing ConcentrationApproveReadApproveWriteWriteRead · RedactedDenyDenyReadRead
Capital / LiquidityApproveReadReadReadWriteDenyDenyDenyRead · EngagementDeny
Policy AttestationApproveReadApproveConsentConsentDenyDenyConsentReadConsent
Product GovernanceApproveReadApproveReadWriteRead · Counsel-LockedRead · RedactedRead · RedactedReadRead
Conduct Risk MIApproveReadApproveReadWriteRead · RedactedDenyDenyReadRead
Regulatory Exam ResponseApproveRead · Board-OnlyApprove · CounselReadWriteRead · Counsel-LockedDenyDenyDenyRead
Stakeholder room access

Room class · audience · restriction · counsel countersign · TTL

Room class Audience role Restriction Counsel countersign Per-recipient link signing TTL Audit-event family
Board roomBoardBoard-OnlyWhere regulator-facingRequiredPer board cycleBOARD-*
Regulator-review roomRegulator-ReviewCounsel-lockedMandatoryRequiredPer engagementREG-*
Investor-review roomInvestor-ReviewRedacted ExternalMandatoryRequired30 dINV-*
Counterparty / pilot roomClient / CounterpartyPer-pilot tenant · MNPI bindingPer-pilotRequiredPer pilotROOM-*
Auditor / assurance roomAuditor / AssuranceScope-bound (engagement letter)Where regulator-touchedRequiredEngagement windowAUD-*
Internal evidence roomEvidence OwnerInternal Onlyn/a (internal)OptionalPer pack publish cycleEV-*
Compliance/legal reviewCompliance / LegalCounsel-lockedMandatoryRequiredPer submissionCOMP-*
Tech/Security war-roomTech / SecurityInternal Only · JITFor regulator-notifyRequiredPer incidentSEC-*
Segregation of duties & approval authorities

Workflow · accountable · approver · SOD pair · compensating control

Workflow Accountable role Approver role Required SOD pair Compensating control Linked policy / control
Evidence pack publishEvidence OwnerFounder/Admin (or Programme)Author ≠ ApproverDual sign-off + per-file footerPOL-013 · CTL-004 · CTL-006
Tier-1 releaseOperationsFounder/Admin + Tech/SecurityBuild ≠ Sign-off · SRE ≠ CISODual sign-off + audit logPOL-006 · CTL-004
MNPI room activationEvidence Owner / OperationsCompliance + Tech/SecurityOwner ≠ ApproverPer-share access review + audit logPOL-003 · CTL-003
Regulator-facing artefactCompliance / LegalCompliance + FounderCounsel countersign required7-step counsel review workflowPOL-005 · POL-014 · CTL-010
Monthly financial closeOperations / FinanceFounder/Admin (or Board quarterly · Auditor annual)Booking ≠ Approval · CFO ≠ AuditorExternal Auditor + audit binderPOL-008 · POL-017 · CTL-009
Vendor reclassificationOperationsCompliance + Board (material)Onboarding ≠ Risk classificationRisk Committee minutes + counsel sign-offPOL-007 · POL-016 · CTL-005
Model output overrideEvidence Owner / ComplianceTech/Security + Compliance (dual on regulator-facing)Build ≠ Override ApprovalOverride register + counsel countersignPOL-010 · POL-011 · CTL-007
Data deletion / retention holdEvidence OwnerTech/Security + ComplianceCustodian ≠ ApproverHold log + audit-event tagPOL-018 · CTL-006
Access reviews · stale & break-glass

Quarterly cadence · 10 review streams · open exceptions

Review ID Role under review Cadence Last review Owner Outcome / open exception State
AR-001Founder / AdminMonthly attestation2026-05-15Board · CISOStanding risk acceptance (DEC-005)Live
AR-002BoardQuarterly2026-05-02Board ChairNoneLive
AR-003Compliance / LegalQuarterly2026-05-09Compliance · External CounselNoneLive
AR-004OperationsQuarterly2026-05-08Operations · Tech/SecurityNoneLive
AR-005Evidence OwnerQuarterly2026-05-12Evidence Owners · ProgrammeNoneLive
AR-006Regulator-ReviewPer engagementn/a · counsel-boundedCompliance · External CounselCounsel session 2026-05-19Under Review
AR-007Investor-ReviewPer sharen/a · awaiting counselCompliance · FounderLocked until counsel sign-offUnder Review
AR-008Client / CounterpartyPer pilot2026-04-30Operations · CompliancePer-pilot template ready · KYC contract pendingUnder Review
AR-009Auditor / AssuranceAnnual + interimn/aOperations · ComplianceExternal auditor engagement letter pendingStale
AR-010Break-glassQuarterly drill2026-02-12Tech/Security · OperationsDrill overdue (target 2026-05-12)Break-Glass · Overdue
Onboarding · offboarding

Lifecycle steps · consent / attestation · evidence captured

Step Onboarding Offboarding Owner Consent / attestation required? Evidence captured
1 · IdentityMicrosoft Entra OIDC sign-up (target) · staging factors todayAccount disable · token revocationTech/SecurityIdentity attestationAuth event log · Entra sign-in log
2 · Role assignmentLeast-privilege default · named approver per roleRoles removed · approvers re-confirmFounder/Admin · Tech/SecurityYes · named-approver attestationRBAC change log
3 · Policy attestationSign POL-018 Policy Attestation + role-specific policiesOff-board attestation loggedCompliance · Tech/SecurityYes · annual + role changeAttestation register (POL-018)
4 · Room bindingsPer-room access reviewed and signedPer-room access removed; per-recipient link signing keys rotatedOperations · Tech/SecurityPer-room consentRoom access ledger (ROOM-*)
5 · MNPI binding (where applicable)MNPI handling attestation · counsel countersign for counterparty/pilotMNPI binding closed · key rotationCompliance · Tech/SecurityYes · counsel countersignMNPI ledger (POL-003)
6 · Training & competencySecurity · privacy · MNPI · code of conductLast attestation archivedTech/Security · ComplianceYes · annualTraining log (TR-EV-ALL-001)
7 · Evidence attestationEvidence Owner per-pack attestationOwner re-assigned · attestation re-signedProgramme · Evidence OwnerYes · per packEvidence pack registry
8 · Cadence registrationAdded to quarterly access-review streamRemoved from stream · revocation evidence loggedTech/Security · Programmen/aAccess review log (AR-*)
External-bundle visibility gates

Four gates · all must be green before any external bundle leaves internal scope

Gate 1
Role-bound audience

Recipient role explicitly listed in the permission matrix; least-privilege scope applied; never sees roles outside engagement.

Met
Gate 2
Counsel countersign

External-facing artefact countersigned by external counsel before the per-recipient room link is signed.

Open · 2026-05-19 session
Gate 3
Per-recipient watermark & link signing

Every external view has a per-recipient watermark and audit-logged access; no anonymous viewing.

Met
Gate 4
Revocation readiness

Single-action revocation pulls all per-recipient signing keys; offboarding runbook proven on rotation drill.

Met
Current posture: three gates met · one open. No external bundle ships under any external role (Regulator-Review, Investor-Review, Client/Counterparty, Auditor) until Gate 2 closes following the 2026-05-19 counsel rule-pack session. Internal roles (Founder/Admin, Board, Compliance, Operations, Evidence Owner, Tech/Security) operate as normal.
Audit trail & evidence preservation

Audit log of role / permission / access-review events

Timestamp (UTC) Actor Role / Permission / Review Action Evidence hash Limitation recorded Next step
2026-05-08 09:00CISO · Programme · External CounselRole taxonomy (10 roles)URPS-TAX — taxonomy publishedsha256:urps…aa01"Internal readiness only."Quarterly review
2026-05-09 11:14CISO · Compliance · ProgrammePermission matrix (21 × 10)URPS-PM — matrix publishedsha256:urps…aa02"Least-privilege default."Refresh on pack/role change
2026-05-10 09:22Operations · Tech/SecurityStakeholder room accessURPS-SRA — 8 room classes mappedsha256:urps…aa03"Counsel-locked for external."Per-share counsel sign-off
2026-05-11 14:08CISO · Programme · External CounselSOD & approvalsURPS-SOD — 8 workflows scopedsha256:urps…aa04"Internal."Re-test on workflow change
2026-05-12 09:50CISO · Operations · ProgrammeAccess reviewsURPS-AR — 10 review streams loggedsha256:urps…aa05"Internal."Close AR-010 break-glass drill
2026-05-13 11:42Tech/Security · Programme · ComplianceOnboarding · offboardingURPS-OO — 8-step lifecycle publishedsha256:urps…aa06"Internal."Run drill on next onboarding
2026-05-15 11:30External Counsel · CEO · Tech/SecurityExternal visibility gatesURPS-VG — 3 of 4 gates metsha256:urps…aa07"No external bundle without all 4 gates."Close Gate 2 post 2026-05-19
2026-05-16 07:55CEO · CISO · ComplianceCentre attestationURPS-ATTESTATION — monthly attestationsha256:urps…aa08"Internal; not regulatory approval."Re-attest monthly
Assumptions and Limitations

What this Centre is — and is not

  • Staging / simulated role & permission data. All role IDs, permission entries, access-review records, evidence hashes, dates, and audit events shown here are seed values for an internal readiness workflow. They are not a live IdP, not a live access-review system, and not a live audit log.
  • Internal readiness workflow only. This Centre captures BLACKSWAN's internal role & permission posture. It is not legal advice, not regulatory approval, not certification, not an audit opinion, and not authorization for external launch.
  • Least-privilege by default. Where a cell is empty or not explicit, the default is Deny. Read-only roles never gain write authority by inference. Approve never implies external sign-off without counsel countersign.
  • External roles are counsel-bound. Regulator-Review, Investor-Review, Client/Counterparty, and Auditor experiences require external counsel countersign on the materials they view before any external visibility gate is opened.
  • Founder-root is a standing accepted risk. Per Programme Decision Log DEC-005, founder-root permanence carries MFA + re-auth + monthly attestation as compensating controls. AR-001 records the operating consequence.