Skip to content

Financial margin wall (mask cost/contract/vendor for PM-tier)

StageBuilding
StatusPartial
Design statusMissing
Estimate1w (M)
ConfidenceMedium
LinearPIN-151 ↗
Linear statusTodo
CycleC15
DesignMISSING — no design canon
Linear epicRuntime, Delivery & Operations
ModuleRuntime & Ops ↗

Priority: Low · Route: /projects/:projectId/detail

Scope

Response-level field masking so PM-tier roles never receive sensitive financial fields — cost basis, contract totals, vendor quotes, insurance exposure, incident financials — gated by 5 tier permissions and enforced per role. (Source: PIN-151.)

Acceptance criteria

  • Response interceptor masks sensitive fields across Bid, Estimate, Project, Document, and Incident data before it reaches the client
  • 5 tier permissions (cost basis, contract totals, vendor quotes, insurance exposure, incident financials) seeded and assigned per role
  • Executive sees all fields; PM-tier sees only what its tier permits; Field User sees no sensitive financials
  • Frontend hides masked columns pre-emptively and renders a placeholder for partially-masked rows
  • Same mechanism extends to mask fields in Cara (AI) responses

Notes

Partly built. Cost budget, contract value and raw vendor pricing are hidden from the assistant-PM level, but a full PM can still see them. The piece that's missing is the field-level masking being switched on for every PM-tier role - right now it exists as a prototype, not yet turned on across the app. We'll handle this properly with the full permission matrix layer (one place to control who sees which fields by role), which also unlocks the same wall for Cara.

Open question for Conor

- Design canon MISSING — no .dc.html maps to this page. Confirm the design source: reuse an existing module export, or schedule a dedicated design pass? (F2)