Roles and approvals

Four roles with scoped capabilities. Critical steps pause at approval gates owned by a specific role.

Access follows a role model with four roles. A role determines which actions a person can take and which approval gates they own. Manage roles and membership on the Teams page.

Roles

Each role carries a specific set of capabilities:

Admin

role

Full access across users, settings, infrastructure, and every approval gate.

  • Manage users and roles, and approve access requests
  • Edit platform settings and integrations
  • Configure agents (model, prompt, tools)
  • Launch delivery runs
  • Act on every approval gate, including account setup and final signoff

Project Manager

role

Runs the delivery and owns the documentation and handover gates.

  • Launch delivery runs (upload a SOW, start the pipeline)
  • Configure agents (model, prompt, tools)
  • Approve the Documentation gate
  • Approve the Final handover and signoff
  • View all runs, infrastructure, costs, and monitoring

Tech Lead

role

Reviews the generated infrastructure and owns the technical gates.

  • Review generated Terraform and approve or reject the Terraform gate
  • Review findings and approve or reject the Audit gate
  • Send a run back to regenerate by rejecting a technical gate
  • View all runs, agents, infrastructure, and costs

Developer

role

Full visibility into runs and output, with no approval authority.

  • View all runs and pipeline output
  • View agents, Terraform, infrastructure, costs, and monitoring
  • No approval authority on any gate
  • Cannot launch runs or manage users and settings

Approval gates

A gate is a point where the pipeline pauses for a human decision. Each gate is owned by one role (the Admin can act on any gate). Approving continues the run; rejecting a technical gate returns it to regeneration.

GateOwnerActions
Account setupAdminApprove
Terraform reviewTech LeadApprove or reject
Audit reviewTech LeadApprove or reject
DocumentationProject ManagerApprove
Final handoverProject ManagerApprove
Reject is available only on the two technical gates, Terraform review and Audit review. A rejection sends the run back to regenerate the Terraform.

Requesting access

Team management is owned by the Admin. Other roles have scoped, view-first access and can request elevated access from the Teams page; an admin confirms the request before any change takes effect.

Was this page helpful?View as llms.txt