Identity and Access¶
DragonPay's Auth0 usage is workforce/operational identity only — P2P senders and recipients never authenticate through it. They enter the Product flow through their credit union's own digital-banking session (PH-01's trusted authentication context) or the hosted Recipient claim experience (CX-01). Auth0 authenticates DragonPay staff and CU operations staff who use the Ops console (OX-01) and DragonPay's own APIs.
Current-lean technology (DR-017, open — ENG-01 §4), reflecting the
parent PE company's shared platform stack. Integration pattern is
ENG01-24's deliverable; the specific pattern described (BFF, guard
chain, no Auth0 Organizations) is contingent on this lean being
confirmed — not yet built, not yet decided, no ADR recorded.
Auth0¶
ENG01-24's deliverable. Not yet built.
Authentication¶
Governed by ENG01-24 and PH01-02 (Establish Trusted Caller Context)
once built.
Authorization¶
Governed by ENG01-24 and PH01-03 (Assign and Enforce Access) once
built.
Roles¶
PH01-03 requires DragonPay to support the initial platform and
Tenant-scoped role catalog. Not yet built.
Permissions¶
PH01-03 governs permission assignment. Not yet built.
Enforcement¶
ENG01-24's deliverable — not yet built. (The specific guard chain,
token-handling, and baseline security-control choices described in an
earlier draft of this page were implementation detail with no ADR or
code behind it; they'll come back once ENG01-24 is actually
implemented.)