Roles¶
Six roles, each with a minimum for every class of action. The server refuses below the minimum before any handler runs; the page hides the controls a role may not press.
| Role | May |
|---|---|
| Viewer | read everything, change nothing |
| Operator | decide on items; start and stop work |
| Asset Owner | Operator, for the cells they own |
| Steward | edit rules, prompts and stage wording |
| Admin | edit manifests and files; manage users and governance |
| Human | everything, including accounts, seats, keys and the switches |
People are added under Settings › Users with an email, a role and the cells they may see. They sign in with Google or Microsoft — SSO is OpenID Connect with PKCE, matched to the list by the email the issuer vouches for — and the passphrase stays the Human's own door. Registering the OIDC client with Google or Microsoft is the Human's act; until it is done, the sign-in buttons are not offered.
Roles and SSO are Pro.