3. Add permissions
Use two Permission Sets: Tutorial salesperson and Tutorial supervisor.
Customers are shared reference data in this exercise, maintained by an administrator. A supervisor must still follow the order state rules.
Goal and starting point
The list and details already use the database. Now prepare separate accounts and distinguish page access, allowed operations, and accessible records.
Three authorization concerns
A Permission Set groups grants for assignment to multiple users. Order ownership comes from ownerId, matched against the signed-in user's ID. The same salesperson Permission Set therefore gives A and B access to different records.
Connect authorization
For the full design workflow, see Describe permissions to AI.
The database resource ID is tutorialOrders. Match Permission Set grants, route resource names, and API checks; a translated display title is not a resource ID.
Create test accounts
As an administrator, open Settings → Users, create salesperson A, salesperson B, and a supervisor, then assign the corresponding roles. Choose your own test passwords.

Test with separate accounts
Create SO-A01 as salesperson A and SO-B01 as salesperson B. Each salesperson should see only their own order; the supervisor should see both.
Copy A's detail URL into B's browser. B must not receive its contents. Ask the AI Agent to test direct API requests too: anonymous reads return 401, forbidden operations are denied, and out-of-scope details do not reveal order data.
In the next chapter, also test a salesperson's forged approval request. A hidden Approve button is not a security boundary.
Next: Add an approval flow.

