Organization ownership and billing-manager roles
Separate organization ownership, billing authority, operational permissions, and platform-level PMA administration.
Before you begin
- An active organization membership.
- Owner authority to assign a billing manager.
- For PMA platform operations, an active platform principal and AAL2 MFA session.
Interface walkthrough
These annotated interface maps describe the current PMA controls. They do not replace a real record review in your workspace.
Controls ownership, billing-manager assignment, organization lifecycle, and commercial requests.
May view plan and usage and handle allowed plan workflows without gaining animal or health permissions.
Platform owner, administrator, support, and finance are independent of customer organization roles.
Step-by-step workflow
Choose the correct authority
Use organization roles for operational work. Use billing-manager status for commercial responsibility. Use platform roles only for PMA business operations.
Assign a current member
A billing manager must already belong to the organization. The assignment and removal are audited.
Protect platform access
Control Vault access requires a platform principal, active account, AAL2 MFA, guarded route, server validation, database authorization, and immutable evidence.
Use support metadata carefully
Platform support sees account identity, memberships, usage, plan state, and internal notes—not unrestricted private husbandry data.
Expected result
Every person has only the authority needed for their role, and billing responsibilities do not silently grant operational or platform privileges.
Safety boundaries
- The hidden route is defense in depth, not authentication.
- Service-role credentials never enter the browser.
- Platform support cannot silently change plans unless granted an administrator role.
- Every sensitive action requires a reason and immutable audit event.
Troubleshooting
A billing manager cannot edit animals
This is intentional. Billing status does not alter normal organization permissions.
A platform owner is asked for MFA
Control Vault requires an AAL2 session. Complete the authenticator challenge in Security Center and reopen the private route.