🔑 Quote access
A client asks for the builder and ticks the areas they want quoted. You decide which of those they actually get, and for how long - the window closes the builder and the quotes it produced. The approval email carries no clickable link, by house rule: it tells them to go to aalvaa.com and sign in themselves.
Loading…
Where the permissions actually live: approving writes the ticked areas into
client_service_permissions (the live table the rate card reads), flips the client's master
approval on, and keeps an immutable snapshot of this decision on the request row. Denying records the
decision only - it never silently strips a grant the client already holds; that is what
Revoke all quote access is for. Every gate is re-checked server-side on every request: this page is
the control surface, not the enforcement.