security-roles
Installation
SKILL.md
Security & Roles
Size-Tier Scope
This variant scales the operating pattern for organizations under 100 people. Keep the controls lightweight, favor owner-led approvals, and introduce automation only where it removes recurring manual work without adding governance overhead.
Purpose
Security configuration determines who can see what, do what, and when. In enterprise systems, security is not an afterthought -- it is a compliance requirement. Auditors examine it. Regulators mandate it. A misconfigured role can expose financial data, violate privacy laws, or allow fraudulent transactions.
Builders need this skill when:
- Setting up user roles and permissions for a new ERP•AI deployment
- Designing access control for sensitive data (financial records, PII, health data)
- Implementing segregation of duties to prevent fraud
- Configuring single sign-on (SSO) and multi-factor authentication (MFA)
- Meeting compliance requirements (SOX, GDPR, HIPAA, SOC 2)
- Designing API security for integration endpoints
- Setting up audit logging and monitoring