Skip to content

Roles

Six roles, each with a minimum for every class of action. The server refuses below the minimum before any handler runs; the page hides the controls a role may not press.

Role May
Viewer read everything, change nothing
Operator decide on items; start and stop work
Asset Owner Operator, for the cells they own
Steward edit rules, prompts and stage wording
Admin edit manifests and files; manage users and governance
Human everything, including accounts, seats, keys and the switches

People are added under Settings › Users with an email, a role and the cells they may see. They sign in with Google or Microsoft — SSO is OpenID Connect with PKCE, matched to the list by the email the issuer vouches for — and the passphrase stays the Human's own door. Registering the OIDC client with Google or Microsoft is the Human's act; until it is done, the sign-in buttons are not offered.

Roles and SSO are Pro.