Roles and permissions
Users receive access matching their role: front desk, service advisor, mechanic, administrator or fleet manager. Permission scope is granted deliberately and can be audited. The most sensitive financial decisions require a separate, single-use identity confirmation - without it the operation is refused, not waved through.