Governance
Staff treats a fleet like an organization. Authorization is in the workflow engine, not in the Staff UI. The console, REST, SDKs, MCP, and Kafka consumers all call engine.start_workflow; RbacGuard runs before the first step. A denied attempt never executes and is still recorded.
Deep model: Staff governance and Governance & approvals. This page is what you configure as a customer.
Structure
| Entity | Role |
|---|---|
| Organization | Tenant boundary. Actors never see another org. |
| Org unit | Team / trust boundary (Finance, Platform). Bindings resolve in a unit. |
| Actor | The worker (or a human principal in the same tree). |
| Role binding | Grants a role on a unit. Effective role walks the tree. |
| Capability | Declared on each workflow. The guard compares role vs capability. |
Roles you will see: OWNER, ADMIN, OPERATOR, VIEWER, AUDITOR. Bind least privilege. A contractor can be OPERATOR on one unit without org-wide keys.
Console: Admin → Roles and Manage staff.
Approval gates
RBAC answers may this actor start this workflow? A gate answers may this specific attempt proceed?
Sensitive workflows pause in an awaiting-approval state. The item lands in Inbox. A human with the approve capability transitions the run forward (execute in your cloud) or rejects it (no side effect). Proposal, approver, and outcome are in the transition log.
sequenceDiagram
participant Actor
participant Engine as Workflow engine
participant Inbox as Staff Inbox
participant Human
Actor->>Engine: start a gated workflow
Engine->>Engine: RbacGuard (propose)
Engine->>Inbox: awaiting approval
Inbox->>Human: review inputs
Human-->>Engine: approve or reject
alt approved
Engine->>Engine: effectful steps in your cloud
else rejected
Engine->>Engine: terminal, no side effect
end
Graduate autonomy: new actors propose-only; relax gates after the audit trail looks right.
Audit
Every Staff and agent action is a workflow run. The transition log is the evidence. Staff Admin → Audit and the audit.* workflows query it read-only, org-scoped:
| Question | Typical query |
|---|---|
| What ran? | Filter by type prefix, actor, status, time |
| What happened in this run? | Full history for one workflow_id |
| What is stuck? | Health scan |
| Compliance pack | Query + per-run history + aggregates over a window |
You never pass another org's id. Denied RBAC and approval decisions are in the same log.
Suggested default posture
| Risk | Examples | Default |
|---|---|---|
| Read | data.*, audit.* | Grant |
| Propose | Drafts, inbox items | Grant to working actors |
| Low-risk write | Refresh a cache, post a message | Grant, review periodically |
| High-risk write | Provision infra, delete, emit financial docs | Gate |
Promote with a role-binding change after you can see the actor's proposals in audit.
