11.0People
A workspace with people in it
Owner, operator and viewer — and the agents in the same list, on a role deliberately weaker than any person's. Two things no agent may ever do: release a held decision, or commit money.
Ridgeline Supply · 5
Priya
Person · 3 of 6 withheld
Runs the day. Can release a held decision, cannot add a bank connection or change who is in the workspace.
- See the workspaceAllowed
- Work items and boardsAllowed
- Release held decisionsAllowed
- Commit moneyNo
- Add or revoke connectionsNo
- Invite and remove membersNo
Priya · Operator. Pick anyone, including the agents, and compare what each may do.
Priya: 3 of 6 withheld.Separation between workspaces is enforced in the database by row-level security keyed on the workspace, not by the interface. Being a member of one grants nothing in another, and a person may hold different roles in each.
Roles
Three roles, and no custom sets
Authority comes with the role rather than being granted one permission at a time. Per-person permission sets are the usual way a workspace ends up unable to answer who can spend money, so there aren't any — the trade is deliberate.
Ridgeline Supply · 5
Priya
Person · 3 of 6 withheld
Runs the day. Can release a held decision, cannot add a bank connection or change who is in the workspace.
- See the workspaceAllowed
- Work items and boardsAllowed
- Release held decisionsAllowed
- Commit moneyNo
- Add or revoke connectionsNo
- Invite and remove membersNo
Priya · Operator. Pick anyone, including the agents, and compare what each may do.
Priya: 3 of 6 withheld.- 11.1OwnerEverything, including billing, connections, membership and handing the workspace on. The only role that can do that last one, and a workspace cannot be left without one.
- 11.2OperatorRuns the day. Works items, releases held decisions, reads everything. Cannot add a connection, change a limit or change who is in the workspace.
- 11.3ViewerReads the workspace and its history, changes nothing. Written for the accountant or the auditor who needs sight without authority.
- 11.4Joining and leavingAn invitation is to one workspace at a named role. Removal takes effect on the next request, and the work a departed member did stays attributed to them.
Agents as members
The same model, a weaker seat
An agent appears in the same list as the people and holds a role like anyone else — one that is deliberately weaker than any person's. That is what makes it possible to ask one question, who can spend money here, and get one answer instead of two.
- 11.5Never grantedReleasing a held decision, and committing above an agent's ceiling. Both are people's to do, and the queue records which person did it.
- 11.6Also withheldAdding or revoking a connection, and inviting or removing members. An agent cannot widen its own reach or change who is watching.
- 11.7GrantedReading the workspace, working items and boards, and proposing anything at all. Proposing is not doing, and the distinction is enforced rather than encouraged.
- 11.8More than one workspaceMembers, connections, agents, limits, credit and history are per workspace and shared by default with nothing. Enforced by row-level security, not by a filter in the interface.
The rest of the system
- 1.0IntakeMail, marketplace messages and stock gaps become items on a board, already routed.
- 2.0WatchCover counted against what is selling, so a line that runs out is flagged early.
- 3.0ActNamed agents work the item and hand it between themselves with the evidence attached.
- 4.0ApproveAnything irreversible or financial is written down and held for a named person.
- 5.0MonitorWhat moved, what is stuck, and what is waiting on you — with the numbers behind it.
- 8.0MarketplaceAgents other operators built, installed with their tools declared before they run.
- 9.0LimitsA ceiling on what runs unattended, and the actions no ceiling ever covers.
- 10.0BoardsOne board held by people and agents alike, where the column follows the owner.
- 12.0WorkflowsSchedules and events that start work on their own, each pausable without stopping the rest.
Start with one agent and one job.