Roles and membership
Grant the smallest role that lets someone do their job. Roles answer what a person may do in this tenant. They do not change which tenant the person is in (that is the hostname; see My tenants).
The roles
Section titled “The roles”| Role | Can | Cannot | Give it to |
|---|---|---|---|
| Admin | Everything on the tenant: Settings (Org, People, Security), roles, onboarding completion, requests to the PRESHai team | Act outside the tenant; change platform-level provisioning (that is Platform ops) | 1 to 3 trusted owners |
| Operator | Run sessions, decide approvals, view records in scope | Change Settings, manage roles, invite or remove members | Service leads, shift owners |
| Member | Run sessions in assigned environments, act on own approvals as permitted | Approve others’ gated actions, change config | Everyone else doing agent work |
Least privilege is enforced: start every new person as Member. Promote to Operator only after they have paired on live approvals. Keep Admins to the smallest group that can cover absences. Every privilege you grant is audit surface.
Granting and changing roles: checklist
Section titled “Granting and changing roles: checklist”- Person signed in at the correct tenant hostname first (role grants land in this tenant)
- Smallest sufficient role selected
- Operator grants: paired on live approvals before solo approval rights
- Change communicated: what they can now do, and where the relevant guide is (Users for members, this section for admins)
- Record reviewed later: new operators’ first approvals spot-checked
Offboarding: checklist
Section titled “Offboarding: checklist”- Remove the member from the tenant promptly on role change or departure
- Reassign any approval responsibilities they held (who decides now?)
- Review their recent sessions and approvals if the departure is sensitive
- Confirm pending invites they sent are still wanted
Common mistakes
Section titled “Common mistakes”| Mistake | Why it hurts | Instead |
|---|---|---|
| Everyone is Admin “to keep it simple” | Settings drift, role confusion, no accountability | Admins stay at 3 or fewer; Operators for leads |
| Role granted in the wrong tenant | Person acts with rights somewhere unexpected | Check hostname before granting |
| Solo approval rights on day one | Rubber-stamping habit forms immediately | Pair first, then grant |
| Never reviewing membership | Stale access accumulates | Quarterly review (see Settings: People) |

