namespace EntitlementBLL.Auth; // Free-text ROLECODE values stored in MENTITLEMENTCLIENTUSERROLE — capability grants layered on // top of a ClientAdmin-tier MENTITLEMENTCLIENTUSER row (see EntitlementDAL.Enums.ClientUserRoleEnum // for the base admin/user tier itself). Resolved once at login/refresh and carried on the JWT's // Capabilities claim (comma-joined, see ClientAccessTokenClaims.ToClaims) so an endpoint can check // capability membership with no DB round-trip. public static class EntitlementClientCapabilityCodes { public const string TechAdmin = "TECH_ADMIN"; public const string CommercialAdmin = "COMMERCIAL_ADMIN"; }