Staff
Staff accounts and role assignment, from fleet SSO (09 §3.13).
The staff list comes from fleet SSO
Fleet SSO verification is unavailable (BK-02), so there is no directory to read and no session to attribute a change to. Nothing here reports how many staff accounts exist.
How access is decided
admin-api enforces named capabilities, not roles. The roles in 09 §1.1 — Super Admin, Ops Manager, QA Analyst, Support Agent, Finance, Content Editor and read-only Analyst — are bundles of those capability names, and the bundles belong to staff administration. A capability list can be audited; a scattered role check cannot.
Assign or remove a staff roleRequires
staff:administer · audited on useRole assignment needs a verified fleet identity to attribute the change to.Deactivate a staff accountRequires
staff:administer · audited on useDeactivation is recorded against the operator who performed it, which requires a verified session.