Documentation
Enterprise GovernanceClean-Room SecurityPillar 4.2

Multi-Tier Clean-Room RBAC & Firewalls

Construction projects unite multiple competing commercial interests on a single site. General Contractors cannot let Owners or Trade Subcontractors see internal labor rates, profit margins, or confidential legal litigation advice. Forge enforces Clean-Room Row-Level and Field-Level Security across every API endpoint and document bundle.

The 8-Tier Role Matrix

Every member invited to an environment is assigned a strictly scoped role that governs data exposure, litigation visibility, and administrative controls:

Owner / General CounselUnrestricted

Full environment administration, financial exposure thresholds, internal contractor margins, privileged legal counsel strategies, and member role governance.

Claims ManagerDefense Admin

Complete claims defense suite: statutory notice generation, SCL dispute bundle compilation, quantum ledgers, and litigation counsel notes.

Project Director / PMOperations

Execution control: schedule imports, CPM baseline variances, daily triage resolution, signal linking, and team invitations.

Client Rep / Employer (External)Clean-Room External

Clean-room external view: milestone progress scorecards, verified delay notices, and hearing bundles with internal contractor margins and counsel notes automatically redacted.

Trade Subcontractor (External)Package Firewalled

Strict trade package scoping: can only view assigned package activities and observations. Daily prolongation rate multipliers and other trades' data are completely hidden.

Auditor / ExpertForensic Audit

Cryptographic verification: access to immutable SHA-256 evidence logs, DCMA 14-point audit assessments, and contemporaneous source references.

EditorContributor

Standard contributor: edit observations, upload site documents, and comment in triage threads.

ViewerRead-Only

Read-only visibility into general dashboard KPIs without administrative or claim generation capabilities.

Field-Level Redaction Mechanism

When an external stakeholder accesses a bundle or an API endpoint, Forge dynamically filters sensitive fields at the serialization layer:

Internal Contractor View
"dailyRateMultiplier": 1.45,
"internalOverheadCost": "€4,500/day",
"counselNotes": "Employer breach on Dwg-04; press for full prolongation under FIDIC 20.1."
External Clean-Room View (Sanitized)
"dailyRateMultiplier": null,
"internalOverheadCost": null,
"counselNotes": "[CLEAN-ROOM NOTICE: Privileged legal remarks reserved for internal contractor distribution]"

External Clean-Room Simulation Preview

General Counsel and Project Managers can toggle the "Simulate External View" switch at any time in /dashboard/defense. This instantly re-renders the active hearing bundle through the eyes of an external Employer or Subcontractor, verifying that zero privileged metadata leaks before issuing formal correspondence.

© 2026 Forge Project Intelligence. All rights reserved.