Team & access
A team is a set of members, each with a role preset and a state, each action attributed and audited. Identity itself is resolved through an accepted invitation, or marked plainly when it cannot be. Maker-checker on sensitive change is building.
Scoped roles, attributed actions, identity resolved by invitation.
- Surface
- team & access
- Each member
- role · state · identity
- Sensitive change
- maker-checker · building
- Every action
- attributed + audited
The book as it stands.
as of 09:48:17Maker pr_2Kp · ops@northwind.co proposed Revoke key ak_live_2Kp at 09:40:12 (rotation). It does not take effect until a different member confirms.
- Ownerpr_7Q4ResolvedLogin · ada@northwind.coActive
- Adminpr_2KpResolvedLogin · ops@northwind.coActive
- Developerpr_9XzPendingInvitation · sam@…Invited
- FinanceOpspr_5FnResolvedLogin · fin@northwind.coActive
- ComplianceReadinesspr_8CrResolvedLogin · risk@northwind.coActive
- Viewerpr_4LmDirectMembershipNoLoginSource · no login sourceActive
A role is a preset of scope
Six presets, from Owner to Viewer: FinanceOps runs the fee record, ComplianceReadiness answers for evidence. Change a role, suspend a member, or remove them, and the action is attributed to whoever made it and recorded as an event.
Maker-checker on what matters · building
Sensitive actions — revoking a live key, changing an owner — will not take effect on one person's say-so. One proposes; another approves. The flow is building; the sequence below shows the designed behaviour.
Identity is resolved, not assumed
A member's identity is resolved through the invitation they accepted, ResolvedLogin. Until then it is PendingInvitation. Where a membership was created with no login source, the console says so, DirectMembershipNoLoginSource, rather than inventing a name.
