Team and roles

Members, role grants, and routing keys.


Policies route stages to roles, and people hold roles. The Team page is where both sides are managed.

Members

Administrators add members with a name, an email, and an initial role set. A member appears in routing immediately: any stage targeting one of their roles can assign them. Editing a member’s roles takes effect on the next stage activation.

During the open pilot no invitation email is sent; sign-in connects when Ocean ID (the suite’s Keycloak identity provider) is enforced. The app-side identity, roles, and history are already in place and survive that switch unchanged.

Roles as routing keys

A role has a display name and a slug (lowercase, stable, like site_engineer). The slug is what policies reference in stages, escalation targets, and rule-added stages. Renaming the display name is free; treat slugs as permanent.

Built-in roles in the demo workspace

SlugPurpose
approval_adminPolicy builder access, team administration, escalation backstop
reviewerDocument review stages
managerFirst-line purchase review
finance_controllerFinance sign-off stages