Skip to main content

Features, Entitlements, and Permissions

Dineax keeps commercial packaging, tenant access, and user access separate.

Key Definitions​

ConceptMeaningExample
Application moduleTechnical or RBAC grouping inside the product.Inventory screens grouped for permissions.
Commercial moduleCustomer-facing package that may be included in a plan or sold separately.Advanced Reporting as a future package.
Canonical featureStable product capability used for entitlement and enforcement.WhatsApp notifications or KDS station limit.
EntitlementTenant-level right to use a capability.Tenant can use a communication capability.
PermissionUser-level right to perform an action.Manager can manage staff access.
Feature flagRelease-control mechanism.Feature available only during rollout.
Operating modelOutlet workflow applicability.Table service or counter service.
Navigation is not authorization

Navigation visibility is not authorization. Backend authorization and approved entitlement enforcement remain authoritative.

How They Work Together​

A tenant may be entitled to a capability, but a specific user still needs the right permission to perform an action. Conversely, a user permission does not mean the tenant has purchased or enabled a future commercial module.

Example​

An outlet manager may have permission to view reports. If advanced reporting is later sold as a commercial module, Dineax must also check whether the tenant is entitled to advanced reporting. Until backend enforcement is applied, permission visibility alone should not be described as commercial access control.