MD · Master data
"Master data" here means what the policy matrix lists under it: vehicle models, pricing groups, charge types, lead sources, checklist items (inspection_item_types), body panels, garages and insurers. Contract templates, company bank accounts and rental companies have rules of their own below. Lookup tables with no organization hold system rows that every tenant shares (R-TEN-03). Code MD.
Not yet a rule
Section titled “Not yet a rule”These questions are open in #76. Each gets a rule with a new ID once it is answered.
- MD open 1 · Brands and partner garages
R-MD-01 · Master data, contract templates and company bank accounts are readable by every member of the organization
Section titled “R-MD-01 · Master data, contract templates and company bank accounts are readable by every member of the organization”- Status: planned
- Example: given a satpam, when he reads vehicle_models, then his organization's models and the system rows come back.
- Refusal: none.
- Who: every member, whatever their roles.
- Source: [Ref] Roles, policy matrix.
R-MD-02 · Adding or changing master data, a contract template or a company bank account needs master_data:write
Section titled “R-MD-02 · Adding or changing master data, a contract template or a company bank account needs master_data:write”- Status: planned
- Example: given a finance user, when she adds a charge type, then it is refused; an admin's goes through.
- Refusal: none: insufficient_privilege (42501) on insert; no effect on update.
- Who: super_admin, admin, maintenance and asuransi hold master_data:write.
- Source: [Ref] Roles, policy matrix.
R-MD-03 · Deleting master data needs master_data:write
Section titled “R-MD-03 · Deleting master data needs master_data:write”- Status: planned
- Example: given an admin, when he deletes a lead source added by mistake and never used, then it is deleted; a used one is refused by R-CONV-11.
- Refusal: none: no effect without the permission.
- Who: super_admin, admin, maintenance and asuransi hold master_data:write.
- Source: [Ref] Roles, policy matrix.
R-MD-04 · App users can't delete a contract template or a company bank account
Section titled “R-MD-04 · App users can't delete a contract template or a company bank account”- Status: planned
- Example: given a super_admin, when she deletes a bank account, then nothing is deleted; it is set inactive instead.
- Refusal: none: no effect, as there is no delete policy.
- Who: every app user.
- Source: [Ref] Roles, policy matrix; D9 (P13).
R-MD-05 · System rows can't be changed or deleted by any organization
Section titled “R-MD-05 · System rows can't be changed or deleted by any organization”- Status: planned
- Example: given the system charge type rent, when a super_admin renames it, then nothing changes.
- Refusal: none: no effect.
- Who: every app user. Only a migration changes them.
- Source: [Ref] Data model V13, lookup tables seeded as system rows (system rows locked).
R-MD-06 · No master data list holds the same name or code twice within an organization
Section titled “R-MD-06 · No master data list holds the same name or code twice within an organization”- Status: planned
- Example: given garage code BK-001, when a second BK-001 is saved in the same organization, then it is refused.
- Refusal: none: unique_violation (23505).
- Who: every writer.
- Source: [Ref] Data model V13, each table's unique key.
R-MD-07 · A lookup code (charge type, lead source, checklist item, body panel) is lower-case snake case
Section titled “R-MD-07 · A lookup code (charge type, lead source, checklist item, body panel) is lower-case snake case”- Status: planned
- Example: given a new charge type, when its code is saved as Late Fee, then it is refused; late_fee is accepted. Checklist items and body panels may also use digits.
- Refusal: none: check_violation (23514).
- Who: every writer.
- Source: [Ref] Data model V13, the code checks.
R-MD-08 · Rental companies are readable with payment:read
Section titled “R-MD-08 · Rental companies are readable with payment:read”- Status: planned
- Example: given a finance user, when she reads rental_companies, then they come back; a checker sees none.
- Refusal: none: hidden.
- Who: super_admin, admin, finance and viewer hold payment:read.
- Source: [Ref] Roles, policy matrix (rental companies, payouts).
R-MD-09 · Adding or changing a rental company needs payment:approve
Section titled “R-MD-09 · Adding or changing a rental company needs payment:approve”- Status: planned
- Example: given a viewer, when he edits a rental company's phone, then nothing changes; a finance user's edit goes through.
- Refusal: none: insufficient_privilege (42501) on insert; no effect on update.
- Who: super_admin, admin and finance hold payment:approve.
- Source: [Ref] Roles, policy matrix (rental companies, payouts).
R-MD-10 · Charge types, lead sources, checklist items and body panels have a required Indonesian name and an optional English name
Section titled “R-MD-10 · Charge types, lead sources, checklist items and body panels have a required Indonesian name and an optional English name”- Status: planned
- Example: given a new body panel, when it is saved with name "Bumper depan" and no name_en, then it is accepted; one saved with only name_en is refused.
- Refusal: none: not_null_violation (23502).
- Who: every writer.
- Source: D29 (master data with two names: name, Indonesian and required; name_en, optional).
R-MD-11 · Where a master data row has no English name, its Indonesian name is shown in English too
Section titled “R-MD-11 · Where a master data row has no English name, its Indonesian name is shown in English too”- Status: planned
- Example: given a lead source with name "Datang langsung" and no name_en, when a user with locale en opens the lead form, then the option reads "Datang langsung".
- Refusal: none.
- Who: apps/web, for every user with locale en.
- Source: D29 (name_en falls back to name).