Authorization
RBAC contains twelve profiles and scope hierarchy global > group > company > unit > sector. Operational access follows stricter SYSTEM > TENANT > COMPANY > UNIT isolation. Active company is mandatory for company data; active unit is mandatory when physical location matters.