Clerk authenticates each participant and supplies a recognized Eval Labs role. Durable server and data authorization separately protect evidence by role and ownership scope. A visible control is not proof that a durable write or cross-user read is authorized.
Role assignment
The recognized application roles are owner, admin, evaluator, and tester. Missing, unassigned, or unknown roles fail closed for protected Eval Labs routes.Current access matrix
Role definitions
Scope rules
- The current analytics label is Analysis, not Global Analysis.
- The standalone Keyboard Review Mode reference is available to every recognized role.
- Keyboard shortcuts never widen the Review Queue route or data scope.
- Saved-suite deep links are available to evaluator and tester roles, but run evidence remains ownership-scoped.
- Real evidence counts only after the relevant authorized durable operation succeeds.

