{
  "artifact": "permission-model-workbook",
  "fields": ["role", "dataAccess", "toolAccess", "actionLimit", "approvalThreshold", "auditVisibility", "environment", "exceptionPath"],
  "actions": ["read", "draft", "recommend", "approve", "execute", "escalate"],
  "gate": "Each role must separate retrieval access from tool authority and define approval thresholds before production use."
}
