RBAC & Permission Matrix
Role-Based Access Control (RBAC)
PLANOVI enforces a dual-layer security model:
- Frontend: Guarded UI components, disabled buttons, and route interception via
RbacContextProvider. - Backend: Postgres Row-Level Security (RLS) policies enforcing company-level isolation and role validation.
Permission Key Format
Permissions are structured as normalized lowercase strings:
$$\text{permission_key} = \text{{module_name}} _ \text{{action_type}}$$
Supported Action Types
| Action Type | DB Action | Description | Helper Method |
|---|---|---|---|
view | VIEW | Read access to screens, lists, or telemetry. | rbac.canView(module) |
create | CREATE | Create new entities, files, or tickets. | rbac.canCreate(module) |
update | UPDATE | Edit existing resources or update states. | rbac.canEdit(module) |
delete | DELETE | Remove records, archive assets, delete tasks. | rbac.canDelete(module) |
others | OTHERS | High-level administrative operations. | rbac.canManage(module) |
Granular Action Helpers
canApprove(module): Authorize democratic resolutions or expense declarations.canAssign(module): Assign field work orders to technicians.canExport(module): Export financial ledger audits and Tauron CSV files.canControl(module): Dispatch telemetry control instructions to inverters and batteries.
Module Permission Matrix
The table below illustrates default permission mappings across roles for the Energy Cooperative features:
| Module / Screen | SuperAdmin / Owner | Admin | Technician | Member | Auditor | Viewer |
|---|---|---|---|---|---|---|
| Energy Dashboard | Full | Full | View | View | View | View |
| My Devices (IoT) | Full / Control | Full / Control | Control / View | View (Own) | View | View |
| Energy Balance | Full | Full | View | View | View | View |
| Member Wallet | Full | View / Manage | None | View / Pay | View | None |
| Financial Ledger | Full | View / Export | None | View (Own) | Audit / Export | None |
| Governance Center | Full | Manage | View / Vote | Vote | Audit | View |
| Technician Queue | Full | Assign | Execute / Update | None | View | None |
| Knowledge Base | Full | Edit / Create | View | View | View | View |
| Jarvis Voice AI | Full | Full | Standard | Standard | Standard | Standard |
| Scheduler & Bookings | Full | Full | View Tasks | Book | View | View |
Usage in Flutter Widgets
To protect a button or screen section, wrap the widget with Consumer<RbacContextProvider>:
Consumer<RbacContextProvider>( builder: (context, rbac, child) { if (!rbac.canControl('energy_devices')) { return const SizedBox.shrink(); // Hide button for unauthorized users }
return ElevatedButton.icon( icon: const Icon(Icons.power_settings_new), label: const Text('Zmień tryb falownika'), onPressed: () => _toggleInverterMode(), ); },);For full-page guards, check rbac.canView(...) in initState() or route builders, rendering the shared ModuleMaintenanceScreen or unauthorized placeholder if permissions are absent.