AddThisFeature

Permission-Aware Action

Decide once how a control behaves when the user is not allowed to use it.

involved User Experience

What it adds

A shared wrapper for buttons, menu items, and links that resolves visibility, disabled state, and the reason a user cannot proceed.

What your agent is told to do

5
  1. 1

    Inventory every action in the app that any role can be denied, and give each one a named capability rather than scattering role comparisons through the components that render it.

  2. 2

    Pick one of three treatments per action and record the choice: hide it, show it disabled with a reason, or show it enabled and let the attempt fail into an upgrade or request-access path. Defaulting everything to hidden makes the product look smaller than it is.

  3. 3

    Whenever an action is disabled, say why in words the user can act on — the role that is required, the prerequisite that is missing, the plan limit that has been reached — and where possible offer the next step.

  4. 4

    Treat prerequisites and permissions through the same wrapper. A save blocked by an incomplete profile and a save blocked by a viewer role should not be two unrelated mechanisms.

  5. 5

    Do not treat the client-side check as enforcement. The server must reject the request independently, and the wrapper exists only to spare the user a pointless attempt.

Edge cases it handles

7
  • Every capability the interface consults must be enforced again on the server for the same request. A hidden button is a courtesy, not a control, and anyone can call the endpoint directly.
  • Hiding, disabling, and explaining are three different decisions with three different costs, and each action needs a deliberate one. Hiding teaches the user nothing; disabling without a reason is worse than hiding; explaining an action they will never be granted is noise.
  • Some denials must not disclose that the thing exists. Telling a user they lack permission on a specific record confirms the record is real, so for those cases present the same not-found response an unrelated identifier would produce.
  • Roles, seats, and workspace membership change while a session is open. The wrapper must re-evaluate on those changes rather than holding whatever was true at first render.
  • A disabled control must still be reachable by keyboard and its reason must be announced, because a tooltip that only appears on hover is invisible to a screen reader and to a touch user.
  • Actions rendered inside a bulk selection need a defined behaviour when the user may act on some of the chosen records and not others — act on the permitted subset and say so, or refuse the whole batch, but not silently drop rows.
  • The reason text must not leak internal policy names, permission strings, or the identity of whoever holds the missing role.

Definition of done

9
  • Every deniable action in the app is declared as a named capability and rendered through the shared wrapper.
  • Each action has a recorded, deliberate treatment: hidden, disabled with a reason, or attemptable.
  • The server rejects every denied action independently of the interface.
  • Denials that would confirm the existence of a private record are indistinguishable from not-found.
  • A role or workspace change updates the affected controls within the same session, without a reload.
  • Disabled controls are keyboard reachable and their reasons are announced to assistive technology.
  • No reason string exposes an internal policy or permission identifier.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.