# Security Tasks

Module scope: authentication, OAuth/token management for connected ad platforms, secrets handling, audit logging, and consent/approval controls. See `docs/TASKS.md` for the full-program index.

| Tasks | Hours |
|---|---|
| 1 | 24 |

---

## Id: 04
- **Phase:** Security
- **Priority:** P0
- **Area:** Security & Governance
- **Task:** Login, OAuth/token management, secrets, audit logs, consent and approval controls
- **Description:** Build authentication for internal users plus OAuth token storage/refresh for each connected ad platform, secure secrets handling, an audit trail of who (or which AI action) did what, and the consent/approval gates that let a human sign off before money is spent or a live campaign is changed.
- **Primary Role/Assignee:** Unassigned
- **Estimated Hours:** 24

---

## Current implementation status

Internal user login (Breeze/Livewire/Volt) is done. OAuth token storage for connected ad platforms, audit logs, and consent/approval gates are not started — today `MetaAdapter` reads a single static token/account id from `.env` (`config/services.php`), not per-user OAuth.
