Formationly Executive Operating System

FEOS Permissions Matrix

The role-based governance model defining who may view, create, edit, assign, approve, archive, export, and permanently remove information within FEOS.

Architecture Library  •  Version 1.0  •  July 2026
Purpose of the Permissions Matrix

Access should reflect responsibility, stewardship, and legitimate need.

The FEOS Permissions Matrix defines the actions available to partners, Premier Partners, regional leaders, administrators, executives, support personnel, and AI-assisted services.

Permissions should protect organizational knowledge while ensuring users have enough access to complete their assigned mission without unnecessary friction.

Governing Access Principle
“Users should receive the access required to fulfill their responsibility—no more and no less.”
Permission Principles

FEOS permissions should follow six governing standards.

01
Least Privilege
Users receive only the access needed for their assigned work.
02
Role-Based Access
Access is assigned through approved roles rather than informal exceptions.
03
Assignment Awareness
Relationship access should reflect active assignments and responsibilities.
04
Separation of Duties
High-impact actions may require review or approval by another role.
05
Auditability
Important permission changes and governed actions should be traceable.
06
Human Authority
AI may recommend actions but may not assume unrestricted authority.
FEOS User Roles

Access begins with clearly defined roles.

01

Partner

Completes training, uses approved resources, manages assigned relationships, records activity, and completes assigned tasks.

02

Premier Partner

Receives advanced capabilities, broader reporting, leadership tools, and limited authority to support other partners.

03

Regional Leader

Supports assigned partners and organizations within a defined region while operating within delegated governance boundaries.

04

Support Administrator

Assists users, corrects approved data issues, manages support workflows, and accesses records needed for legitimate support activity.

05

Platform Administrator

Manages users, permissions, assignments, configuration, records, governance, audit review, and platform operations.

06

Executive Administrator

Holds the highest business authority for policy, governance, sensitive actions, permanent deletion, and enterprise oversight.

AI

AI Executive Guide

Reads authorized context, generates recommendations, prepares drafts, and assists users without independently assuming human approval authority.

Permission Legend

Permission levels should use consistent language.

Allowed
The user may perform the action directly.
Limited
The action is restricted by assignment, scope, or business rule.
Request
The user may submit the action for approval.
Prohibited
The user may not perform the action.
Not Applicable
The capability does not apply to the role.
Core Permissions Matrix

Baseline role authority

Capability Partner Premier Regional Support Platform Admin Executive AI Guide
View Own Profile Allowed Allowed Allowed Allowed Allowed Allowed Context
View Assigned Organizations Allowed Allowed Regional Support Need Allowed Allowed Authorized Context
Create Organization Allowed Allowed Allowed Limited Allowed Allowed Prohibited
Edit Assigned Organization Limited Limited Regional Support Need Allowed Allowed Suggest Only
Create Contact Allowed Allowed Allowed Limited Allowed Allowed Prohibited
Record Conversation Allowed Allowed Allowed Limited Allowed Allowed Draft Only
Create Task or Follow-Up Allowed Allowed Allowed Allowed Allowed Allowed Suggest Only
Reassign Organization Request Request Limited Prohibited Allowed Allowed Prohibited
Archive Organization Request Request Request Request Allowed Allowed Prohibited
Permanently Delete Record Prohibited Prohibited Prohibited Prohibited Request Authorized Prohibited
Manage User Roles Prohibited Prohibited Request Prohibited Allowed Allowed Prohibited
View Audit History Own Actions Limited Regional Support Need Allowed Allowed Authorized Context
Workspace Access

Workspace visibility should be role-aware.

EXECUTIVE HEADQUARTERS
All Active Partners
Content and metrics should adapt to role and responsibility.
QUICKSTART & READINESS
All Partners
Progress, certification, and assessment information remains user-specific.
CONVERSATION CENTER
Approved Partners
Access may depend on training completion or readiness status.
EXPANSION CENTERS
Role or Audience Based
Christian School content may remain unavailable until approved for release.
KCRM
Assignment Based
Users see records connected to assignments, leadership scope, or support need.
ADMINISTRATION
Authorized Roles Only
Includes permissions, audit, reassignment, merging, archival, and configuration.
Sensitive Actions

High-impact actions require additional governance.

Permanent deletion should require executive authorization, a documented reason, and an audit record.
Bulk export of relationship or contact data should be restricted and monitored.
Organization merges should require duplicate validation and preservation of both prior histories.
User role elevation should require an authorized administrator and documented approval.
Changes involving sensitive personal or ministry information should be limited to legitimate operational need.
AI Permission Boundaries

AI receives contextual access, not independent ownership.

May read only the records and fields authorized for the current user and task.
May prepare summaries, recommendations, questions, briefings, and drafts.
May identify missing fields, overdue tasks, potential duplicates, and governance concerns.
May not permanently alter authoritative records without explicit user approval.
May not send messages, reassign ownership, export data, or delete records without authorized action.
Must distinguish verified record data from inference, recommendation, or missing information.
Permission Lifecycle

Access should evolve with the user’s role and status.

STEP 1
Request
A user, manager, or process identifies the access need.
STEP 2
Approve
An authorized role validates responsibility and scope.
STEP 3
Assign
The approved role or permission is applied.
STEP 4
Review
Access is periodically reviewed for continued need.
STEP 5
Revoke
Access is removed when the role, assignment, or legitimate need ends.
Audit Requirements

High-impact access changes should remain traceable.

Record who granted, changed, suspended, or revoked a role.
Preserve the prior permission state and effective date.
Record the reason, approval source, and related assignment.
Log sensitive exports, deletions, merges, reassignment, and administrative overrides.
Make audit history available only to authorized governance roles.
Implementation Guidance

Permissions should be implemented before advanced KCRM workflows.

Define all initial roles and eliminate overlapping titles before implementation.
Separate workspace visibility from record-level action authority.
Use assignments, regions, and responsibilities to narrow access where appropriate.
Test denied, limited, request-only, and approved scenarios—not only successful access.
Review the permissions matrix whenever a new role, workspace, object, or sensitive capability is introduced.

Clear authority protects trusted stewardship.

The FEOS Permissions Matrix ensures that partners can complete their mission, leaders can provide responsible oversight, administrators can govern the platform, and organizational knowledge remains protected.