Skip to main content

11.0People

A workspace with people in it

Owner, operator and viewer — and the agents in the same list, on a role deliberately weaker than any person's. Two things no agent may ever do: release a held decision, or commit money.

Ridgeline Supply · 5

Priya

Person · 3 of 6 withheld

Runs the day. Can release a held decision, cannot add a bank connection or change who is in the workspace.

  • See the workspaceAllowed
  • Work items and boardsAllowed
  • Release held decisionsAllowed
  • Commit moneyNo
  • Add or revoke connectionsNo
  • Invite and remove membersNo

Priya · Operator. Pick anyone, including the agents, and compare what each may do.

Priya: 3 of 6 withheld.

Database row-level security enforces workspace separation. Membership in one workspace grants no access to another, and a person may hold a different role in each.

Roles

Three roles, and no custom sets

Authority comes from one of three roles: owner, operator or viewer. Keeping those roles fixed makes it possible to answer who can spend money in a workspace.

Ridgeline Supply · 5

Priya

Person · 3 of 6 withheld

Runs the day. Can release a held decision, cannot add a bank connection or change who is in the workspace.

  • See the workspaceAllowed
  • Work items and boardsAllowed
  • Release held decisionsAllowed
  • Commit moneyNo
  • Add or revoke connectionsNo
  • Invite and remove membersNo

Priya · Operator. Pick anyone, including the agents, and compare what each may do.

Priya: 3 of 6 withheld.
  • 11.1OwnerEverything, including billing, connections, membership and handing the workspace on. The only role that can do that last one, and a workspace cannot be left without one.
  • 11.2OperatorRuns the day. Works items, releases held decisions, reads everything. Cannot add a connection, change a limit or change who is in the workspace.
  • 11.3ViewerReads the workspace and its history, changes nothing. Written for the accountant or the auditor who needs sight without authority.
  • 11.4Joining and leavingAn invitation is to one workspace at a named role. Removal takes effect on the next request, and the work a departed member did stays attributed to them.

Agents as members

The same model, a weaker seat

An agent appears in the same list as the people and holds a role like anyone else — one that is deliberately weaker than any person's. That is what makes it possible to ask one question, who can spend money here, and get one answer instead of two.

  • 11.5Never grantedReleasing a held decision, and committing above an agent's ceiling. Both are people's to do, and the queue records which person did it.
  • 11.6Also withheldAdding or revoking a connection, and inviting or removing members. An agent cannot widen its own reach or change who is watching.
  • 11.7GrantedAgents can read assigned workspace data, work items and boards, and submit proposals. Releasing a held proposal remains a separate permission for people.
  • 11.8More than one workspaceMembers, connections, agents, limits, credit and history are scoped per workspace. Database row-level security enforces that boundary.

Start with one agent and one job.