Roles, permissions and entity access

Access in Governax is decided by two independent things: the role you hold in the organisation, and whether you can reach a given entity. Confusing the two accounts for most access questions we get.

Two separate questions#

The two access questions
QuestionAnswered by
What am I allowed to do?Your organisation role: owner, admin or member.
Which entities can I open at all?Owners and admins reach every entity. Everyone else needs to be a member of that specific entity.

Holding a role does not imply reaching an entity, and reaching an entity does not imply permission to change things in it.

The three organisation roles#

Organisation roles
RoleIntent
ownerFull control. Every organisation has at least one and the last one cannot be removed.
adminFull control in practice, including reaching every entity.
memberOrdinary user of the product. What they can do is decided per entity.

If you are looking for a read-only role, it is not here. Read-only is a property of your relationship to one entity, not to the whole company, so it lives on the entity axis as reader. That is what lets you give an auditor one entity’s ledger without giving them every entity’s.

The three entity grades#

Being able to open an entity is not the same as being able to change it. Everyone granted an entity holds one of three grades in it, and they form a ladder: each one includes everything below it.

Entity grades, weakest first
GradeAPI valueCan do
ReaderreaderRead this entity's ledger and roster, and run a verification. Changes nothing.
OperatoroperatorEverything a reader can, plus connect and disconnect this entity's evidence sources.
Entity adminentity_adminEverything an operator can, plus decide who else is in this entity and at what grade.

It is entity_admin rather than admin because the bare word already means two other things here: a Governax platform administrator, and an administrator of a whole organisation. An entity admin is neither. They run exactly the entity they were granted and have no standing in any other, nor in the organisation itself.

Reader is the default. Someone granted an entity with no grade chosen, including anyone who accepts an invitation carrying an entity, is a reader until somebody deliberately raises them. That is the safe end on purpose: a new route added to the product is closed to them until a decision is made about which grade should reach it.

What is actually gated today#

This is where documentation usually drifts from reality, so here is the precise position.

Actions and what they require
ActionRequires
Read the ledger, run a verification, list membersReader
Connect or disconnect an evidence sourceOperator
Add someone to an entity, or change their gradeEntity admin
Invite someone into one entityEntity admin
Invite someone into the organisationOrganisation owner or admin
Update organisation profile metadataOrganisation owner or admin
Create or delete an entityOrganisation owner or admin

Which entities you can open#

Owners and admins bypass entity membership entirely and are entity admins of every entity in the organisation, including ones created later. Everyone else must be granted the specific entity, and hitting an entity they were not granted returns NOT_ENTITY_MEMBER.

Governax platform administrators#

Separate from organisation roles, Governax staff hold a platform administrator role used to review new workspaces and, if necessary, suspend an organisation. It is not something a customer is granted, and it is not part of your role model.