⚠ Tier labels are advisory today · NOT a runtime RBAC
The persona pills (canonical / board / analyst / project / forensic / admin) organize information architecture, not access. Today: each gated surface accepts a UI-side persona elevation (workspace localStorage + X-Kokon-Persona header); Phase 524 backend gate is audit mode by default — every gated route call is logged to the security event log, none are blocked. Reading a label as "auth" overstates what shipped.
Strict enforcement needs three things: (a) flip KOKON_PERSONA_ENFORCE=strict; (b) wire PersonaRequiredGuard on every route a label promises (today only some — OFAC refresh, journal compact, investigation seal); (c) lock the persona switcher behind real auth (today self-promote is one click). Tracked as Phase 524.1; commit history (PHASE-A → UX-FIX) names the gap honestly so no reader mistakes "labeled" for "enforced".
Operator · Portfolio canonical
Daily-driver portfolio steward. Mission Control is the only canonical surface here; everything else drills out of it.
Operator · Per-company canonical
Single-company daily home. Pipeline stages + connector coverage + digital twin + analysis history + trust integrity verify.
Board · CEO consumption only
Board / CEO consumption surfaces. NOT the operator home — these are briefs assembled for executive audiences.
Analyst · Model-risk SR 11-7 tier
Quantitative / model-risk drill-in. Causal counterfactual · brain calibration (ECE/MCE/Brier) · OOD detector · doctrine RAG. Engineering twin (KOKON self-monitoring) by default · Banking twin available for client diagnostics.
Project PM · Rollout single-source-project
Rollout PM for a single source project — contract integrity, readiness, posture. NOT per-company; per-project.
Forensic Investigator investigative · not a SAR determination
Case work surface. Phase 552-563 stack: 27 deterministic detectors · Bayesian confidence · counterfactual sweep · Brain/OFAC/GLEIF connectors. Every finding is a pattern warranting review — never a legal conclusion.
Admin / Infra system health · doctrine
System-tier surfaces: kernel pin · doctrine · sealed receipts · nightly / sentinel / harness. NOT portfolio decisioning. Sub-grouped into Doctrine/Identity, Governance, Adversarial Testing, Infra Plumbing.
⓻·A Doctrine / Identity kernel pin · math constants · methodology contract
⓻·B Governance override trail · secrets/policies · event store
⓻·C Adversarial Testing validation harness · nightly · sentinel · graders · verdict
⓻·D Infra Plumbing substrate · arin22 ops · wave VI structured reasoning