Entitlement resolver — why can this account do that?
The vocabulary ladder made walkable (§ vocabulary ruling): MODULE (a product area, on/off with cascade) → FLAG (a rollout switch) → CAPABILITY (what a role may do) → ENTITLEMENT (what THIS account gets). Four different questions; support tickets die when they get conflated. This page answers one composed question — “why does account X have (or not have) Y?” — by walking the four rungs and naming WHO set each one, WHERE, WHEN. READ-ONLY by design: each rung deep-links to its one write surface (Modules · Platform control · Roles). A resolver that could also edit would be a second write path.

One account + one ability in, the full resolution chain out — the page support opens first.
Demo dataComposed
Account · ability · platform — the resolver walks the ladder below. Demo shows one worked question.

The resolution — top of the ladder down

module
AI suite — ON for Fanogram
The module is live platform-wide; its cascade reaches every linked surface (chat drafts · voice · autopilot). If this rung were OFF, nothing below would matter — that is what cascade means.
set by: FG admin (platform scope) · 2026-06-14 · modules.html
Modules →
flag
voice-sales rollout — 100%
Fully rolled out; no cohort gating left. A flag is a rollout switch, not a permission — retiring it after full rollout is a Platform-control chore.
set by: release lane · 2026-07-02 · control.html
Control →
capability
creator role MAY sell AI voice
The role’s row on the platform × function matrix allows it. A capability belongs to a ROLE — no account is ever granted one directly.
set by: roles LOCKED baseline · matrix v3 · roles.html
Roles →
entitlement
@veravoss HAS voice sales — trained + consented
The account-level fact: voice model trained 2026-07-18, consent recorded, not suspended. This is the only rung that mentions the account — and the only one an account-level action (suspension, consent withdrawal) can change.
granted: automatic on training completion · orchestration · audited
Account →
RESOLVEDYes — @veravoss can sell AI voice on Fanogram.4 rungs green · weakest rung: none · chain audited end to end

Same walk, failing — the point of the page
The resolver’s value is the DENIED case: it names the ONE rung that says no, so nobody flips four switches hoping. Here the module and flag pass, the capability passes — the ENTITLEMENT fails (no trained voice), so the fix is training + consent, not an admin toggle.

?
@novabelle · AI voice sales · Fanogrammodule ✓ · flag ✓ · capability ✓ · entitlement ✗ — no trained voice model
Denied at rung 4
?
@rosamarln · send messages · Fanogrammodule ✓ · flag ✓ · capability ✗ — account frozen strips the role · entitlement not reached
Denied at rung 3
READ-ONLY COMPOSITION · each rung is read from its owning surface (modules · control · roles · account) and edited ONLY there · EFFECT · the resolver answers; it never grants — a page that could do both would be a second write path, and there is one write path per truth