Access Control Engine

The Access Control Engine is Verolex’s permission and feature-gating system. It keeps the experience consistent across pages and prevents “feature tease” by making it clear what is available now, what is preview-only, and what unlocks next — always with consent.

Classification: Permission & Feature Gating Scope: Pages • Tools • Uploads • Voice • Memory

Purpose

Verolex serves multiple professional groups and multiple access tiers. The Access Control Engine enforces those boundaries so that: (1) users don’t see tools they cannot use, (2) privacy defaults are preserved, and (3) upgrades feel like a clear change in capability — not confusion.

Why This Matters

  • Consistency: your level determines what is real vs. preview across every Access, Library, and teaching page.
  • Privacy: uploads and persistent memory remain off by default and require explicit opt-in where supported.
  • Clarity: when something is a preview, Verolex labels it as a preview. No silent assumptions.
  • Stability & support: when a tool fails intermittently, gating and eligibility checks help isolate whether it’s access, consent, or the voice subsystem.

Primary Functions

1) Dynamic page restrictions

Controls who can view a page (public, trial, paid tiers, staff), and what components appear when a visitor is not eligible.

2) Tool privilege enforcement

Determines whether interactive tools are enabled, disabled, or shown in preview mode — including voice tools, forms, dashboards, and workspace links.

3) Tier-driven feature availability

Applies your commercial logic reliably: what a user can do at each tier and what changes the moment they upgrade.

4) Consent + safety enforcement

Verolex does not treat uploads, memory, or saved artifacts as “on” by default. The engine respects consent rules and page-level permissions.

5) Upload behavior (real vs. preview)

Supports your model: Upload hubs may exist as examples. A paperclip affordance can be: (a) a real upload (eligible level), or (b) a preview demonstration (not eligible) — clearly labeled either way.

6) Time-boxed access (optional)

If you sell “one increment of access time,” the engine can enforce the time window by membership expiration and/or page rules — so access ends cleanly without manual intervention.


Examples

Uploads

  • Eligible level: upload control is enabled on pages that support it.
  • Not eligible: upload control may appear as a demo affordance, but is labeled “Preview” and does not accept files.
  • Always: no automatic storage; consent governs any persistent use.

Voice

  • Voice appears only on pages where voice is permitted.
  • Voice use depends on access + consent (and any page-specific rules you set).
  • Language defaults to English unless the user asks to switch.

Teaching pages

  • Mode switches (VCV/VVC) belong at the top of designated teaching pages.
  • Access pages should stay calm and readable — teaching components are placed intentionally, not everywhere.

Interactions

  • Access Group Matrix: defines who belongs to what group and what they can use.
  • Consent Management: controls memory, saved artifacts, and upload handling rules.
  • VCV/VVC Routing: keeps voice and visual tools in their correct lanes and only on approved pages.

One-Line Summary

The Access Control Engine ensures the right tools appear for the right person, at the right level, with the right consent — every time.