Role-based access and admin governance
• Admin menu is hidden for non-admin users.
• Admin APIs return 403 for non-admin requests.
• Session is cookie-based and validated on server.
By Access Role:
By Department: