The four categories worth protecting
- Access: inviting users, changing roles, revoking members, connecting integrations.
- Money: payout destinations, refunds, credit notes, write-offs, pricing floors.
- Commitment: contract terms, signature material, warranty scope, change orders that alter price.
- Destruction: purging records, bulk operations, and anything that cannot be undone.
Confirmation is not approval
A confirmation dialog asks the person already performing an action whether they meant it, and it protects against slips. An approval requires a different, more senior identity to authorize the action before it proceeds, and it protects against judgement. Systems that offer only confirmation and describe it as approval are describing a control they do not have.
Credentials are an owner boundary even inside a team
Signing tokens, invitation tokens, portal access tokens and integration credentials are not ordinary fields on a record. Anyone who can read them can act as someone else, so they should be excluded from ordinary queries and restricted to senior roles, independent of who is allowed to work on the record they belong to.