Playground features

Roles, tenants and an audit log

Roles, per-tenant isolation and the audit trail an enterprise buyer asks for — the authorization half of SSO, never the sign-in half

Decides what each signed-in person is allowed to do, keeps one company’s data apart from another’s, and writes down who changed what. It begins after sign-in — you bring the sign-in itself.

Three walled courtyards side by side with unbroken walls, a differently shaped key hanging on each inner door, and a long stamped ribbon unspooling beneath them

A feature of the Playground

This is a feature of the Vibe Coder Playground. It runs inside the Playground, with its audit record and its caveats beside it.

Download the Playground See pricing

The mistake it removes

Two failures, both silent. A role model with no identity behind it (looks complete, denies nothing), and tenant isolation enforced in application code rather than at the data layer — where one forgotten WHERE clause serves another customer's rows and nothing errors.

What you still have to do

The feature cannot own your secrets, your host or your legal obligations. This is the part it deliberately does not claim.

What lands in your project

node

  • node/enterprise-kit.js

can()/assertCan() over a ranked role table, withTenant() to scope every query, and auditLog() for the trail SOC 2 asks about. Roles come from the CALLER's identity — the block refuses to guess.

What you supply

Get it

Download the Playground See pricing

A feature of the Vibe Coder Playground.

Questions

Is Roles, tenants and an audit log audited?
No. No full audit has been run against this block yet, which is not the same as a pass. What is verified about it is listed on this page, and what is not is listed beside it.
What do I still have to do myself?
A real identity provider you wire yourself — OIDC or SAML sign-in, a session, and a membership record mapping each signed-in user to a tenant and a role — because can()/assertCan() read the role the CALLER hands them and will grant whatever you pass. This is the exact failure the source codebase discloses about itself: a complete ranked role table that could not deny anything, because nothing bound a request to a non-owner role. Until identity is bound, every request resolves to one actor and the role check is documentation.
How do I get this?
It is a feature of the Vibe Coder Playground. Download the Playground, and see the pricing page for what each plan includes.

All Playground features · Free code blocks · Learn to build from zero · The coding guide