DOCS
Roles and permissions
Five roles, eight capabilities. This matrix is a single module in the codebase — the navigation, the API guards and the roles table in Settings all read it, so what you see here is what the server enforces.
| CAPABILITY | admin You, plus one backup | lead Owns one team | developer Everyone else | security Redaction and audit | billing Seats and invoices |
|---|---|---|---|---|---|
| Team numbers | Yes | Own team | Own team | Yes | — |
| Open a person | Yes | Own team | Self | — | — |
| Read prompt text | Yes | Own team | Self | Flagged | — |
| Ship skills as PRs | Yes | Yes | — | Yes | — |
| Change nudges | Yes | Own team | — | — | — |
| Manage devices | Yes | — | — | Yes | — |
| Redaction + retention | Yes | — | — | Yes | — |
| Seats and billing | Yes | — | — | — | Yes |
Reading a cell
Own teammeans a lead sees their own team’s numbers and nobody else’s. Self means a developer sees their own prompts and their own score, which is the default posture: coaching, not comparison. Flagged gives security the prompts that tripped a secret rule and nothing more, so an incident can be worked without a general licence to read.