Team and roles
Members, role grants, and routing keys.
Policies route stages to roles, and people hold roles. The Team page is where both sides are managed.
Members
Administrators add members with a name, an email, and an initial role set. A member appears in routing immediately: any stage targeting one of their roles can assign them. Editing a member’s roles takes effect on the next stage activation.
During the open pilot no invitation email is sent; sign-in connects when Ocean ID (the suite’s Keycloak identity provider) is enforced. The app-side identity, roles, and history are already in place and survive that switch unchanged.
Roles as routing keys
A role has a display name and a slug (lowercase, stable, like site_engineer). The slug is
what policies reference in stages, escalation targets, and rule-added stages. Renaming the
display name is free; treat slugs as permanent.
Built-in roles in the demo workspace
| Slug | Purpose |
|---|---|
approval_admin | Policy builder access, team administration, escalation backstop |
reviewer | Document review stages |
manager | First-line purchase review |
finance_controller | Finance sign-off stages |