Role-based access control with page-scoped permissions, the permission catalogue, approval policy for mutating actions, and an append-only audit trail with tamper-evident storage.