SCOPE GUARD: Tiered export permissions
YOUR SPEC, AS I READ IT
1. Admins can restrict which fields appear in an export
2. Admins can restrict who may run an export
3. Export runs are logged for audit
Correct the split before you read anything below it.
1. RESTRICT FIELDS SHARPEN
Matched: "exports leak internal pricing to resellers"
"We had to stop resellers exporting at all because the sheet
carries our margin column." Contoso Retail, deal blocker
Customers describe field-level control on ONE column, not a
configurable set. Say margin, not fields.
2. RESTRICT WHO MAY RUN SPLIT
Matched two different mechanics that would be built and
tested separately: turning export off per role, and
requiring approval per run.
3. AUDIT LOG NO EVIDENCE
Nothing in the feedback describes this. That is not an
argument against it. Compliance requirements do not arrive
through support tickets.
MISSING FROM THE SPEC ADD
Scheduled exports keep running after someone loses access.
Raised by several customers. No requirement covers it.
REJECTED MATCHES
"Export timeout" theme: a performance problem, not a
permissions one. Dropped, and its numbers with it.