Skip to main content

Users and access

Identity provider: OIDC (cloud tenant in client installations). On client servers public auth is ON by default. In Development it is off unless you enable it.

Enforcement happens on the backend (ROLE_SCOPES, require_scope).

Operate views (screenshots)

ViewGuide
Users & Accessoperar-vistas/users-access
My profileoperar-vistas/mi-perfil
Approvalsoperar-vistas/aprobaciones

Full index: Console — Operate.

Roles

RoleIn short
adminoperate the society, SOUL/prompts, users; not dev:write
operatorapprove, deploy, governance
memberConversation UI; :own reads
viewersociety read-only, no inbox
serviceM2M (gated executor, graph emitters)

dev:write and * are superadmin-only.

Chat

Public copilots sign in through OIDC (bootstrap script on the copilot host).

Ownership

ownership_enforce is off in all environments today.

Machine identity

The gated executor has its own M2M identity. The CLI prefers the sis-cli app; otherwise SOCIETY_INTERNAL_TOKEN.