Gates access inside a tenant with a {resource}_{action} role system on Django/DRF — a deny-by-default permission class that maps the ViewSet action to a codename and checks has_permission/has_object_permission, plus explicit guards on every custom @action. Use when adding or reviewing a DRF permission class, wiring permission_classes on a ViewSet, deciding who may list/create/update/delete a resource, guarding a custom @action, or fixing an unguarded endpoint. Not for tenant row-scoping in get_queryset (see multi-tenancy) or generic serializer/router setup (see drf-api).