Who it's for6 authorities2 built-in tiers

Six authorities. In a business of fifteen, about three people.

These are separable authorities rather than separate job titles. In a small business the first four collapse onto two or three humans, and the permission splits exist so they can be pulled apart later without a rebuild.

People

The splits are the design, not an afterthought.

The permission catalogue reads like a design document because it is one. Resetting somebody's second factor is separate from user administration, because after a reset the account is reachable with a password alone.

Operations lead or owner-operator

Admin tier

The person who runs the business day to day and is the only one who sees the commercial picture end to end.

  • Every action, unconditionally. The admin tier cannot be denied a permission, so a broken permission row can always be repaired from inside the product
  • Invoices and who owes what, estimate margins, competitor pricing, and what the agents cost
  • Agent instructions, models and tool scopes, edited in Settings rather than deployed
  • The schedules, the digest, the controlled lists, the roles and the integrations

Delivery team member

Member tier

The work, not the money. Two of the inclusions are deliberate and worth knowing.

  • Tasks, risks, documents and the calendar, plus drafting social posts and seeing that their own hours arrived
  • Generating documents from templates, because the people who write a tender response are rarely the people who administer the deployment
  • Triaging the tender board and the media feed, because a pipeline only two admins can touch is a pipeline nobody maintains
  • Not invoices, not estimates, not competitor monitoring, and not approving an agent action

Approver

Its own permission

Deliberately absent from the member baseline and deliberately not implied by managing agents, because approving is the moment an action nobody reviewed executes under that person's name.

  • The pending action queue: destructive tool calls waiting on a decision
  • The standing rules that pre-authorise a narrow class of them
  • The inbound-email review screen, gated on the same permission
  • Declining is not gated at all. Refusing is the fail-safe direction, so anyone can say no

Commercial lead

Admin-gated screens

Not a separate tier today, but a distinct set of screens behind admin-only permissions for one stated reason: an estimate is cost rates, on-costs, subcontractor buy prices and gross margin, and redacting the money from it leaves nothing.

  • Estimates, quotes, invoices and AR ageing, plus the rate card
  • Competitor monitoring and price history
  • Promoting an estimate to a quote, which is kept separate from editing estimates on purpose
  • That separation is what lets this become its own role later without a rebuild

Deployment operator

Not a product role

Whoever stands the deployment up and keeps it running. This is the person a security questionnaire is really addressed to.

  • Environment configuration, the deploy script, the database, and the provider choices for storage, email and SMS
  • Whether single sign-on, SCIM, passkeys, campaign tracking and guardrails are switched on at all
  • Backup and recovery beyond the verified backup the deploy script takes before every migration
  • The host, the network and the operating environment

Machine consumers

Authenticated, permissioned

Not people, but they authenticate and they hold permissions, so somebody will ask about them.

  • An API client holding a key, calling the REST endpoints or an agent directly
  • An MCP client such as a desktop assistant, reaching the tool registry over stdio or HTTP, read-only unless writes are enabled
  • An identity provider provisioning users and groups over SCIM
  • All three hit the same actor enforcement as a browser session, so a key cannot do what the person behind it could not

Roles you can add without waiting for us.

Custom roles, per-person grants and per-person denies are stored in the database and resolved at request time. A read-only board member, a subcontractor who watches the tender board without moving cards, a helpdesk role that resets a second factor without granting itself one, an estimator who builds scenarios but cannot put a priced document in front of a customer: each of those is a configuration, not a release.