Permissions beyond the interface — Isla Smyth
← All workBusiness applications · 2026

Permissions beyond the interface

Tenant-scoped data access, shared permission policies and staff-level overrides with regression coverage.

  • Django REST Framework
  • JavaScript
  • SQL
  • Testing

The context

Across existing applications, I worked on how access is enforced at the server and data layers, as well as how it is reflected in the interface.

What I worked on

  • Scoped data queries and foreign-key selections to the requesting organisation.
  • Added cross-organisation regression tests for reads and writes.
  • Refactored application roles around shared permission definitions.
  • Implemented staff permission overrides backed by role defaults, cached lookups and transactional updates.

Lessons learned

Hiding a button does not enforce access. A consistent policy needs to reach the endpoint and the query, with tests that exercise requests which should be denied.