Orkestia
Blog
Staff & Agents

Governance

Roles, approval gates, and audit — how a customer constrains what actors may do and proves what happened

Staff treats a fleet like an organization. Authorization is in the workflow engine, not in the Staff UI. The console, REST, SDKs, MCP, and Kafka consumers all call engine.start_workflow; RbacGuard runs before the first step. A denied attempt never executes and is still recorded.

Deep model: Staff governance and Governance & approvals. This page is what you configure as a customer.

Structure

EntityRole
OrganizationTenant boundary. Actors never see another org.
Org unitTeam / trust boundary (Finance, Platform). Bindings resolve in a unit.
ActorThe worker (or a human principal in the same tree).
Role bindingGrants a role on a unit. Effective role walks the tree.
CapabilityDeclared on each workflow. The guard compares role vs capability.

Roles you will see: OWNER, ADMIN, OPERATOR, VIEWER, AUDITOR. Bind least privilege. A contractor can be OPERATOR on one unit without org-wide keys.

Console: Admin → Roles and Manage staff.

Approval gates

RBAC answers may this actor start this workflow? A gate answers may this specific attempt proceed?

Sensitive workflows pause in an awaiting-approval state. The item lands in Inbox. A human with the approve capability transitions the run forward (execute in your cloud) or rejects it (no side effect). Proposal, approver, and outcome are in the transition log.

sequenceDiagram
  participant Actor
  participant Engine as Workflow engine
  participant Inbox as Staff Inbox
  participant Human
  Actor->>Engine: start a gated workflow
  Engine->>Engine: RbacGuard (propose)
  Engine->>Inbox: awaiting approval
  Inbox->>Human: review inputs
  Human-->>Engine: approve or reject
  alt approved
    Engine->>Engine: effectful steps in your cloud
  else rejected
    Engine->>Engine: terminal, no side effect
  end

Graduate autonomy: new actors propose-only; relax gates after the audit trail looks right.

Some capabilities stay platform-locked in beta (for example fiscal-document emission) even if you grant the role. Treat platform locks as a ceiling above your bindings.

Audit

Every Staff and agent action is a workflow run. The transition log is the evidence. Staff Admin → Audit and the audit.* workflows query it read-only, org-scoped:

QuestionTypical query
What ran?Filter by type prefix, actor, status, time
What happened in this run?Full history for one workflow_id
What is stuck?Health scan
Compliance packQuery + per-run history + aggregates over a window

You never pass another org's id. Denied RBAC and approval decisions are in the same log.

Suggested default posture

RiskExamplesDefault
Readdata.*, audit.*Grant
ProposeDrafts, inbox itemsGrant to working actors
Low-risk writeRefresh a cache, post a messageGrant, review periodically
High-risk writeProvision infra, delete, emit financial docsGate

Promote with a role-binding change after you can see the actor's proposals in audit.