Access follows a role model with four roles. A role determines which actions a person can take and which approval gates they own. Manage roles and membership on the Teams page.
Roles
Each role carries a specific set of capabilities:
Admin
roleFull access across users, settings, infrastructure, and every approval gate.
- Manage users and roles, and approve access requests
- Edit platform settings and integrations
- Configure agents (model, prompt, tools)
- Launch delivery runs
- Act on every approval gate, including account setup and final signoff
Project Manager
roleRuns the delivery and owns the documentation and handover gates.
- Launch delivery runs (upload a SOW, start the pipeline)
- Configure agents (model, prompt, tools)
- Approve the Documentation gate
- Approve the Final handover and signoff
- View all runs, infrastructure, costs, and monitoring
Tech Lead
roleReviews the generated infrastructure and owns the technical gates.
- Review generated Terraform and approve or reject the Terraform gate
- Review findings and approve or reject the Audit gate
- Send a run back to regenerate by rejecting a technical gate
- View all runs, agents, infrastructure, and costs
Developer
roleFull visibility into runs and output, with no approval authority.
- View all runs and pipeline output
- View agents, Terraform, infrastructure, costs, and monitoring
- No approval authority on any gate
- Cannot launch runs or manage users and settings
Approval gates
A gate is a point where the pipeline pauses for a human decision. Each gate is owned by one role (the Admin can act on any gate). Approving continues the run; rejecting a technical gate returns it to regeneration.
| Gate | Owner | Actions |
|---|---|---|
| Account setup | Admin | Approve |
| Terraform review | Tech Lead | Approve or reject |
| Audit review | Tech Lead | Approve or reject |
| Documentation | Project Manager | Approve |
| Final handover | Project Manager | Approve |
Requesting access
Team management is owned by the Admin. Other roles have scoped, view-first access and can request elevated access from the Teams page; an admin confirms the request before any change takes effect.