Users and access
Identity provider: OIDC (cloud tenant in client installations). On client servers public auth is ON by default. In Development it is off unless you enable it.
Enforcement happens on the backend (ROLE_SCOPES, require_scope).
Operate views (screenshots)
| View | Guide |
|---|---|
| Users & Access | operar-vistas/users-access |
| My profile | operar-vistas/mi-perfil |
| Approvals | operar-vistas/aprobaciones |
Full index: Console — Operate.
Roles
| Role | In short |
|---|---|
admin | operate the society, SOUL/prompts, users; not dev:write |
operator | approve, deploy, governance |
member | Conversation UI; :own reads |
viewer | society read-only, no inbox |
service | M2M (gated executor, graph emitters) |
dev:write and * are superadmin-only.
Chat
Public copilots sign in through OIDC (bootstrap script on the copilot host).
Ownership
ownership_enforce is off in all environments today.
Machine identity
The gated executor has its own M2M identity. The CLI prefers the sis-cli app; otherwise SOCIETY_INTERNAL_TOKEN.