Skip to content

Roles and membership

Grant the smallest role that lets someone do their job. Roles answer what a person may do in this tenant. They do not change which tenant the person is in (that is the hostname; see My tenants).

Role Can Cannot Give it to
Admin Everything on the tenant: Settings (Org, People, Security), roles, onboarding completion, requests to the PRESHai team Act outside the tenant; change platform-level provisioning (that is Platform ops) 1 to 3 trusted owners
Operator Run sessions, decide approvals, view records in scope Change Settings, manage roles, invite or remove members Service leads, shift owners
Member Run sessions in assigned environments, act on own approvals as permitted Approve others’ gated actions, change config Everyone else doing agent work

Least privilege is enforced: start every new person as Member. Promote to Operator only after they have paired on live approvals. Keep Admins to the smallest group that can cover absences. Every privilege you grant is audit surface.

  • Person signed in at the correct tenant hostname first (role grants land in this tenant)
  • Smallest sufficient role selected
  • Operator grants: paired on live approvals before solo approval rights
  • Change communicated: what they can now do, and where the relevant guide is (Users for members, this section for admins)
  • Record reviewed later: new operators’ first approvals spot-checked
  • Remove the member from the tenant promptly on role change or departure
  • Reassign any approval responsibilities they held (who decides now?)
  • Review their recent sessions and approvals if the departure is sensitive
  • Confirm pending invites they sent are still wanted
Mistake Why it hurts Instead
Everyone is Admin “to keep it simple” Settings drift, role confusion, no accountability Admins stay at 3 or fewer; Operators for leads
Role granted in the wrong tenant Person acts with rights somewhere unexpected Check hostname before granting
Solo approval rights on day one Rubber-stamping habit forms immediately Pair first, then grant
Never reviewing membership Stale access accumulates Quarterly review (see Settings: People)