Skip to main content

Staff console menu

Staff

Staff accounts and role assignment, from fleet SSO (09 §3.13).

The staff list comes from fleet SSO

Fleet SSO verification is unavailable (BK-02), so there is no directory to read and no session to attribute a change to. Nothing here reports how many staff accounts exist.

How access is decided

admin-api enforces named capabilities, not roles. The roles in 09 §1.1 — Super Admin, Ops Manager, QA Analyst, Support Agent, Finance, Content Editor and read-only Analyst — are bundles of those capability names, and the bundles belong to staff administration. A capability list can be audited; a scattered role check cannot.

Assign or remove a staff roleRequires staff:administer · audited on useRole assignment needs a verified fleet identity to attribute the change to.
Deactivate a staff accountRequires staff:administer · audited on useDeactivation is recorded against the operator who performed it, which requires a verified session.