Roles & Permissions
Six roles are available. Each stage has a designated approver — only that role can unlock the next stage. The same person cannot provide both L1 and L2 approval on the same stage.
Approver by stage
| Stage | L1 approver | L2 approver |
|---|---|---|
| 1 · PRD | BA | — |
| 2 · FRS | BA | — |
| 3 · User Stories | BA | — |
| 4 · Design Docs | Architect | Tech Lead |
| 5 · Code | Tech Lead | Architect |
| 6 · Unit Tests | Test Lead | — |
| 7 · CI/CD | Architect | — |
| 8 · Verify | Test Lead | — |
Stages 4 and 5 require dual L1 + L2 approval from two separate named approvers. Every other stage takes a single L1 approval. The Developer and PM roles are never designated approvers.
danger
Role enforcement is strict. If your logged-in role is not the designated approver, the system blocks the approval and shows a denial box before prompting for a name. A BA cannot approve Stage 4 or above.
info
Every approval captures Approver Full Name + Role + Timestamp — recorded in
docs/sdlc/session.md under the stage entry.