--- since: 0.6.0 --- # Permissions Permissions should be evaluated from the authenticated identity and project membership. Typical hierarchy: ```text System │ ├── administrator │ └── Project │ ├── owner/admin ├── maintainer ├── contributor └── viewer ``` Exact roles are implementation-specific. ## Security principle Every API operation that reads or mutates project/issue data should enforce authorization server-side. A user being able to see a project page is not sufficient evidence that the user is authorized to mutate every issue within that project.