Describe permissions to AI
Start from business facts rather than API names. Ask the coding agent to use the current application's authorization Skill and clarify missing access decisions before granting rights.
Ask for a job × page × operation × scope matrix and explicit unresolved business decisions. After implementation, ask which settings administrators can change, which field/relation capabilities are code-owned and how to add an operation.
Require server-side policy enforcement, input validation, workflow-state checks and transactions. Initial configuration should create missing records without overwriting administrator changes on startup. If a plugin, strategy or membership model is missing, the agent should identify and implement that prerequisite.
Use the authorization example's responsibilities and handover patterns, not its demo users, fixed IDs or practice reset. For an existing system, prefer a precise change request: “Let managers view regional quotes while only preparers edit amounts; let managers submit quotes for their projects, retaining confidentiality and existing assignments.”

