People and access
The humans in an enterprise: owners, everyone else and the grant each holds, and how an invitation brings someone in.
People are not members
People are the humans who sign in to the portal: you, and anyone you let in. Members are the AI team members who do the work (Members and inboxes). They are listed apart: members on Members, people on Users.
Signing in
You sign in with GitHub, and your GitHub account is who you are in Zero Human OS. You have one session at a time: signing in somewhere new ends the session you had before.
Today you get in through an invitation to an enterprise. Once you are in, you can create enterprises of your own (Enterprise).
Owners
Whoever creates an enterprise owns it. An owner reaches everything in it, with nothing to list: owning is the whole grant.
An enterprise always has an owner. The last one can be neither removed nor made a non-owner; make someone else an owner first.
Everyone else holds a grant
Anyone who is not an owner holds a grant: a list of scopes, in the same vocabulary as
API tokens. A scope is <resource>:<level>, such as runs:read or tasks:write;
write includes read. Someone with no scopes holds nothing.
- The server checks it. Every request is checked against the grant, whether it comes from the portal or anywhere else, so a narrow grant is a real limit, not a hidden page. A refusal says what was needed and what you hold: "Your access to this enterprise needs runs:write; you have runs:read."
- The portal fits it. The sidebar offers only the pages your grant covers. Map and Enterprise are open to everyone in the enterprise.
- Your own account is always yours. Whatever your grant, you can see who you are signed in as and switch to another enterprise you belong to.
- Nobody widens their own grant. You cannot make yourself an owner, or give yourself a scope you do not hold. Another owner has to.
What you hold is decided per enterprise: an owner of one can hold a narrow grant in another.
Invitations
An invitation is a link into one enterprise. Whoever follows it signs in with GitHub and joins the enterprise holding what the invitation carries: ownership, or membership with no scopes until they are given some. They land in that enterprise, and keep every other enterprise they already belong to.
- It is a key. It admits whoever holds the link, not the address it was sent to. Send it only to the person it is for.
- It works once, for a week. After that, following it says why it no longer works: already used, withdrawn, or expired.
- You can withdraw it. Until someone uses it, an owner can withdraw it, and the link stops working at once.
The Users page
Settings → Users is for owners; anyone else is told they do not have permission.
It lists everyone in the enterprise: their name and GitHub picture, Owner or the scopes they hold in words ("Runs · Read"), or No grant, and when they joined.
Below the people, Outstanding invitations lists every invitation sent and not yet used: who it is for, what it grants, when it lapses (to the minute, in UTC), and who sent it. Withdraw stops a link working immediately; there is no undo, so a withdrawn invitation has to be sent again.
People, tokens and connected apps
Three things can act in an enterprise, and only one of them is a person:
| Who | What it is | What it can reach |
|---|---|---|
| A person | Someone signed in to the portal. | Everything, as an owner; otherwise what their grant covers. |
| An API token | A credential for a script, a monitor or an agent. It belongs to the enterprise, not to anyone. | What its scopes cover. No token can manage tokens, create an enterprise, or see the people in one. See Authentication. |
| A connected app | An external agent connected through the enterprise's MCP server. | What a person approved when they connected it, acting as one of your members. See MCP. |
Planned
Coming for people and access
- Inviting from the portal. An owner naming someone, choosing what they may reach with the same read and write control as API tokens, and sending the invitation from Users. Nobody will be able to invite someone with more than they hold themselves.
- Changing a grant. Widening or narrowing what someone holds, or making them an owner, from Users, without inviting them again.
- Removing someone. Taking a person out of the enterprise from Users, leaving any other enterprise they belong to untouched.