PLATFORM — THE CONTROL PLANE
The organization's decisions — in a plane that enforces itself.
Governance decisions are made here and take effect the same moment: who reaches what, what is enabled for whom, how much balance, who approves. No circular waiting to be applied — the decision is the application.
The control plane is the single place where the organization sets roles, enablement, balance, and approvals; every change applies to the gate instantly and is recorded like any other event — even administrators' permissions are roles under the same rule.
Enablement scope by role — illustrative numbers; your policy decides the reality.
ROLES
Permission is granted by role — not by trust, not by a polite ask.
The same matrix the gate reads on every request: four illustrative roles are enough to read the logic — your own roles fill the rows.
| ROLE | FILES | INTERNAL ASSISTANTS | BALANCE |
|---|---|---|---|
| Employee | ● own department folders only | ● those enabled for the role | ● a daily number he sees himself |
| Manager | ● the whole department | ● all the department's assistants | ◐ approves the team's requests |
| Financial analyst | ● finance sources and nothing else | ● the analysis assistants | ● within the team cap |
| Guest auditor | ○ registers — temporary read | — | — |
Illustrative examples — the real matrix builds from your identity system's roles.
ENABLEMENT
Tools and sources: off until you decide otherwise.
The default in Seamless Enterprise is that a source does not exist until it is enabled by a named decision: who enabled it, for whom, with what scope. Switching off is a decision at the same speed — one switch, one entry.
BALANCE & APPROVALS
Cost is a daily number; the exception is an approval that carries a name.
Every team has a declared cap, every employee a number they see themselves. What crosses the cap doesn't become an invoice — it becomes an approval request waiting at the role you named.
- A cap before the surprise. The estimate precedes execution — the overrun pauses for approval, not for a later apology.
- Approval in context. The manager sees the request, its cost, and its reason on one card — and decides from where they sit.
- A trail for every decision. The approval is an entry with its owner's name and date — ready for finance's and audit's questions.
GOVERNING THE PLANE ITSELF
Whoever sets the gate passes through the gate.
Admin permissions are roles too: the least privilege that suffices, separation between who proposes and who approves, and an entry for every edit.
- Least privilege. The balance admin doesn't touch roles; the enablement admin doesn't read others' registers — each scoped to the task.
- Four eyes where it matters. Sensitive changes are proposed by one role and approved by another — per your policy.
- The plane under the register. Every edit to roles or switches is a full entry: who, what, when, the before and the after.
A plane not subject to its own register has a register you cannot trust.
For the security team: review the plane with your own eyes.
A security review session walks roles, separation, and entries — and what doesn't fit your model, we say plainly.
EVALUATION QUESTIONS
System owners ask these first.
Do you apply least privilege to administrators themselves?
Yes — administration is split into roles: balance, enablement, roles, register — and no role combines them except by your explicit decision. The least privilege that suffices is the default.
Can approvals be delegated when a manager is away?
Yes — a declared, time-bound delegation visible in the plane; decisions are recorded under the delegate's name with the delegation referenced. No approvals from a borrowed account.
Are changes to the plane itself recorded?
Yes — an entry like any entry: who edited, what it was before and after, and when. Setting the gate is an event governed by the gate itself.
How fast does revoking a permission take effect?
Immediately — the plane is not a system synced later; it is the reference the gate reads on every request, so the next request is checked against the new state.
CONTINUE THE PATH
From the plane to the rest of the platform.
Set it once — let it enforce.
Forty-five minutes on a demo build: we draft your starting roles under your names, then push one change and watch it apply and get recorded the same moment.