[{"data":1,"prerenderedAt":38},["ShallowReactive",2],{"$f3pn5xoivio0qn":3},{"href":4,"title":5,"description":6,"kind":7,"mark":7,"planned":8,"contributors":9,"provenance":7,"html":10,"headings":11},"\u002Fdocs\u002Fcompany\u002Fpeople","People and access","The humans in an enterprise: owners, everyone else and the grant each holds, and how an invitation brings someone in.",null,false,[],"\u003Ch2 id=\"people-are-not-members\">People are not members\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>People\u003C\u002Fstrong> are the humans who sign in to the portal: you, and anyone you let in. \u003Cstrong>Members\u003C\u002Fstrong> are the AI team\nmembers who do the work (\u003Ca href=\"\u002Fdocs\u002Fcompany\u002Fmembers\">Members and inboxes\u003C\u002Fa>). They are listed apart: members on\n\u003Cstrong>Members\u003C\u002Fstrong>, people on \u003Cstrong>Users\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch2 id=\"signing-in\">Signing in\u003C\u002Fh2>\n\u003Cp>You sign in with GitHub, and your GitHub account is who you are in Zero Human OS. You have one session at a time:\nsigning in somewhere new ends the session you had before.\u003C\u002Fp>\n\u003Cp>Today you get in through an invitation to an enterprise. Once you are in, you can create enterprises of your own\n(\u003Ca href=\"\u002Fdocs\u002Fcompany\u002Fenterprise\">Enterprise\u003C\u002Fa>).\u003C\u002Fp>\n\u003Ch2 id=\"owners\">Owners\u003C\u002Fh2>\n\u003Cp>Whoever creates an enterprise owns it. An owner reaches everything in it, with nothing to list: owning is the whole\ngrant.\u003C\u002Fp>\n\u003Cp>An enterprise always has an owner. The last one can be neither removed nor made a non-owner; make someone else an\nowner first.\u003C\u002Fp>\n\u003Ch2 id=\"everyone-else-holds-a-grant\">Everyone else holds a grant\u003C\u002Fh2>\n\u003Cp>Anyone who is not an owner holds a \u003Cstrong>grant\u003C\u002Fstrong>: a list of scopes, in the same vocabulary as\n\u003Ca href=\"\u002Fdocs\u002Fapi\u002Fauthentication\">API tokens\u003C\u002Fa>. A scope is \u003Ccode>&lt;resource&gt;:&lt;level&gt;\u003C\u002Fcode>, such as \u003Ccode>runs:read\u003C\u002Fcode> or \u003Ccode>tasks:write\u003C\u002Fcode>;\n\u003Ccode>write\u003C\u002Fcode> includes \u003Ccode>read\u003C\u002Fcode>. Someone with no scopes holds nothing.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>The server checks it.\u003C\u002Fstrong> Every request is checked against the grant, whether it comes from the portal or\nanywhere else, so a narrow grant is a real limit, not a hidden page. A refusal says what was needed and what you\nhold: &quot;Your access to this enterprise needs runs:write; you have runs:read.&quot;\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The portal fits it.\u003C\u002Fstrong> The sidebar offers only the pages your grant covers. \u003Cstrong>Map\u003C\u002Fstrong> and \u003Cstrong>Enterprise\u003C\u002Fstrong> are open\nto everyone in the enterprise.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Your own account is always yours.\u003C\u002Fstrong> Whatever your grant, you can see who you are signed in as and switch to\nanother enterprise you belong to.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Nobody widens their own grant.\u003C\u002Fstrong> You cannot make yourself an owner, or give yourself a scope you do not hold.\nAnother owner has to.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>What you hold is decided per enterprise: an owner of one can hold a narrow grant in another.\u003C\u002Fp>\n\u003Ch2 id=\"invitations\">Invitations\u003C\u002Fh2>\n\u003Cp>An invitation is a link into one enterprise. Whoever follows it signs in with GitHub and joins the enterprise\nholding what the invitation carries: ownership, or membership with no scopes until they are given some. They land\nin that enterprise, and keep every other enterprise they already belong to.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>It is a key.\u003C\u002Fstrong> It admits whoever holds the link, not the address it was sent to. Send it only to the person it\nis for.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>It works once, for a week.\u003C\u002Fstrong> After that, following it says why it no longer works: already used, withdrawn,\nor expired.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>You can withdraw it.\u003C\u002Fstrong> Until someone uses it, an owner can withdraw it, and the link stops working at once.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"the-users-page\">The Users page\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>Settings → Users\u003C\u002Fstrong> is for owners; anyone else is told they do not have permission.\u003C\u002Fp>\n\u003Cp>It lists everyone in the enterprise: their name and GitHub picture, \u003Cstrong>Owner\u003C\u002Fstrong> or the scopes they hold in words\n(&quot;Runs · Read&quot;), or \u003Cstrong>No grant\u003C\u002Fstrong>, and when they joined.\u003C\u002Fp>\n\u003Cp>Below the people, \u003Cstrong>Outstanding invitations\u003C\u002Fstrong> lists every invitation sent and not yet used: who it is for, what it\ngrants, when it lapses (to the minute, in UTC), and who sent it. \u003Cstrong>Withdraw\u003C\u002Fstrong> stops a link working immediately;\nthere is no undo, so a withdrawn invitation has to be sent again.\u003C\u002Fp>\n\u003Ch2 id=\"people-tokens-and-connected-apps\">People, tokens and connected apps\u003C\u002Fh2>\n\u003Cp>Three things can act in an enterprise, and only one of them is a person:\u003C\u002Fp>\n\u003Cdiv class=\"prose__table\">\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Who\u003C\u002Fth>\n\u003Cth>What it is\u003C\u002Fth>\n\u003Cth>What it can reach\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>A person\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>Someone signed in to the portal.\u003C\u002Ftd>\n\u003Ctd>Everything, as an owner; otherwise what their grant covers.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>An API token\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>A credential for a script, a monitor or an agent. It belongs to the enterprise, not to anyone.\u003C\u002Ftd>\n\u003Ctd>What its scopes cover. No token can manage tokens, create an enterprise, or see the people in one. See \u003Ca href=\"\u002Fdocs\u002Fapi\u002Fauthentication\">Authentication\u003C\u002Fa>.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Cstrong>A connected app\u003C\u002Fstrong>\u003C\u002Ftd>\n\u003Ctd>An external agent connected through the enterprise's MCP server.\u003C\u002Ftd>\n\u003Ctd>What a person approved when they connected it, acting as one of your members. See \u003Ca href=\"\u002Fdocs\u002Fmcp\">MCP\u003C\u002Fa>.\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003C\u002Fdiv>\n\u003Cdiv class=\"prose__planned\">\n\u003Cp class=\"prose__flag\">Planned\u003C\u002Fp>\n\u003Ch2 id=\"coming-for-people-and-access\">Coming for people and access\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Inviting from the portal.\u003C\u002Fstrong> An owner naming someone, choosing what they may reach with the same read and write\ncontrol as API tokens, and sending the invitation from \u003Cstrong>Users\u003C\u002Fstrong>. Nobody will be able to invite someone with more\nthan they hold themselves.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Changing a grant.\u003C\u002Fstrong> Widening or narrowing what someone holds, or making them an owner, from \u003Cstrong>Users\u003C\u002Fstrong>, without\ninviting them again.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Removing someone.\u003C\u002Fstrong> Taking a person out of the enterprise from \u003Cstrong>Users\u003C\u002Fstrong>, leaving any other enterprise they\nbelong to untouched.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fdiv>\n",[12,16,19,22,25,28,31,34],{"id":13,"text":14,"level":15,"planned":8},"people-are-not-members","People are not members",2,{"id":17,"text":18,"level":15,"planned":8},"signing-in","Signing in",{"id":20,"text":21,"level":15,"planned":8},"owners","Owners",{"id":23,"text":24,"level":15,"planned":8},"everyone-else-holds-a-grant","Everyone else holds a grant",{"id":26,"text":27,"level":15,"planned":8},"invitations","Invitations",{"id":29,"text":30,"level":15,"planned":8},"the-users-page","The Users page",{"id":32,"text":33,"level":15,"planned":8},"people-tokens-and-connected-apps","People, tokens and connected apps",{"id":35,"text":36,"level":15,"planned":37},"coming-for-people-and-access","Coming for people and access",true,1791124519554]