Field masking (field-level role masking)¶
| Stage | Estimated |
|---|---|
| Status | Deferred |
| Design status | In progress |
| Estimate | 2w (L) |
| Confidence | Low |
| Linear | PIN-151 ↗ |
| Linear status | Todo |
| Cycle | C15 |
| Design | Design ↗ |
| Linear epic | Platform Foundation |
| Module | Settings & Admin ↗ |
Priority: Low
Scope¶
Role-based masking of sensitive financial fields (cost, margin, contract totals, vendor quotes, insurance limits, incident amounts) across Bid, Estimate, Project, Document, and Incident views — each role sees only the tiers it's permitted to see, with masked values rendered as a placeholder instead of hidden entirely. (Source: PIN-151.)
Acceptance criteria¶
- Sensitive financial fields are masked per role across Bid, Estimate, Project, Document, and Incident views
- 5 permission tiers: cost basis, contract totals, vendor quotes, insurance exposure, incident financials
- Executive sees all figures; PM sees only the tiers granted (e.g. contract totals, not cost basis); Field User sees no sensitive financials
- Masked columns are hidden proactively in lists/grids rather than shown then blanked
- Cells with mixed access render masked values as "—" with a tooltip
- Masking applies consistently everywhere the field appears, not just on primary screens
Notes¶
PM sees "masked" on cost budget; post-launch, no rush for v1
Open question for Conor¶
-