Staff & Agents
Console
Operate a fleet from staff.orkestia.dev — inbox, staff tree, activity, sessions, and the admin surfaces
The Staff console is the operator surface. Production URL: https://staff.orkestia.dev. Every button starts a named staff.*, agents.*, or data.agents.* workflow — there is no side channel around RBAC.
Operate (daily)
| Page | Path | Use it for |
|---|---|---|
| Dashboard | /dashboard | Live sessions and what needs attention |
| Inbox | /inbox | Approvals, failed runs, budget blocks, first-run checklist |
| Staff | /staff | Units, actors, org map; hire and inspect |
| Activity | /activity | What actors are doing now |
| Sessions | /sessions | Run history, open a session for the trace |
Inbox is the approval queue and the triage list. Pair it with Lumen when you need transition-level traces.
Publish (optional)
If your org uses Staff to draft social/video content, Meta, YouTube, and LinkedIn compose pages send drafts to Inbox for human review. They are not required to run generic actors.
Build (definition)
| Page | Path | Use it for |
|---|---|---|
| Configs | /configs | Runtime configs that power actors |
| Skills | /skills | Reusable workflow-backed skills |
| MCP servers | /mcp-servers | Register, refresh, and inspect tool servers |
| Schedules | /staff/schedules | Wake an actor on a cron without a human invoke |
See Configs, skills, MCP.
Admin
Collapsed by default in the sidebar.
| Page | Path | Use it for |
|---|---|---|
| Manage staff | /staff/manage | Units, actors, roles at once |
| Roles | /staff/roles | Grant and inspect access |
| RBAC seats | /staff/rbac | Paid actor seats and agt_ token export |
| Runner groups | /runner-groups | Pools that host sessions |
| Repositories | /repositories | Where Orkestia may write code (coding agents) |
| Cost / Pricing | /cost, /pricing | Spend analytics and $/1M overrides |
| Org settings | /org-settings | Limits, capabilities, notifications, memory org flag |
| Audit | /staff/audit | Event log |
Intervene
| Lever | When |
|---|---|
| Pause the actor | Misbehavior or an incident freeze |
| Stop / cancel a session | This run is wrong; keep the actor |
| Retry a failed run | Transient runner or tool error |
| Revoke a role binding | Pull a capability immediately |
| Revoke exported tokens | Compromised agt_ credential |
Runner capacity is a hard dependency. Invoke cannot succeed if no compatible agent runner group is active. That failure is separate from the customer-facing Runners CI product. See Agent runner groups.
Mental model
- Staff console
- Workflow engine
- RbacGuard
- Run + session
- Transition log / audit
- Staff console→ starts named workflows →Workflow engine
- Workflow engine→RbacGuard
- RbacGuard→ authorize →Run + session
- Run + session→Transition log / audit
- Transition log / audit→ inbox + audit →Staff console
