ADR-0128: The GLOBAL Cascade Carries Administration, Never Content¶
- Status: accepted (2026-08-28 — row 41, his catch: "in the global scope we can set the ergon qms team but the projects will staff the roles differently. Here things get interesting"; ruling: "I like your proposal about the administrative and content class differentiation on the global scope. Please do this")
- Date: 2026-08-28
- Deciders: Nicolas Burri
- Relates to: V005 (the cascade this amends), ADR-0121 (
PermissionClassificationTest— the derived classification that becomes load-bearing here), ADR-0127 §1 (the library whose staffing forced the question), V016/ADR-0031 (BASE_READ's own path, untouched), ADR-0122 (the org-anchor cascade, unchanged), ADR-0012 (admin ≠ content — extended to the cascade itself).
Context¶
Library authors must be staffed AT the GLOBAL scope: workflow gates resolve roles effective in the scope, and nothing cascades INTO GLOBAL. But V005's first disjunct cascades a GLOBAL assignment into every scope of every organization — so staffing the QMS team with authoring roles at GLOBAL would hand them content reach (VIEW/CREATE/EDIT…) into every customer project. Latent today (the landing staffed nobody at GLOBAL); it materializes at the first real library staffing. The boundary the product defends everywhere else would be breached by its own staffing model.
Decision¶
From an assignment at the GLOBAL scope, only ADMINISTRATIVE-class permissions cascade into
other scopes. CONTENT-class permissions from a GLOBAL assignment are effective in GLOBAL alone.
The class is the one ADR-0121's guard already derives — this ADR makes that classification a
structural fact of the permission model, not documentation. Assignments at a MANDATOR anchor are
unchanged (ADR-0122's sovereignty-flows-downhill stays whole-class, inside one organization's
boundary). BASE_READ is unchanged by construction: V016 reads it through its own RLS path,
keyed on "held via a global assignment", never through the scope-set cascade.
Consequences by persona: QMB@GLOBAL = full library authoring, zero reach into any project;
lqms-admin unchanged (administrative class); the Base Reader unchanged; a GLOBAL assignment
that today silently meant "content everywhere" stops existing as a concept.
Rejected: a per-assignment no-cascade flag (a second mechanism where a guarded class already exists); moving the library out of GLOBAL (churn against ADR-0127 §1 for the same result).
Consequences¶
- V005's disjunct 1 gains the class condition (migration); the RLS authorized-scope resolution
and
lqms_effective_permissionsagree by construction — one predicate, both places. PermissionClassificationTestbecomes load-bearing: a mis-classified new permission now changes RUNTIME reach, so the guard's argued classifications are the boundary's spec.- Any existing GLOBAL assignment of a content-carrying role changes meaning at migration time; the migration header must inventory live grants on real installations and the deploy notes must say what narrowed (on lqms.ch: only Base Reader rows at GLOBAL carry content-class permissions — BASE_READ — which the V016 path keeps working; nothing else narrows today).