Ring & Knock
Operations workspaceCascade Stays — PNW
Manager preview activeManager route view selected locally. Full internal review surfaces are visible in this browser preview.
Draft work
Local work draftStage review work
Open Work

Local draft only. Nothing is dispatched or written outside this browser preview.

Roles

Internal workspaceManager reviewDraft mode
Summary viewDecision surface first

Settings Guardrails

Source-static proof

Role Governance Matrix

Review-only governance
Roles & permissions

Default scopes and denied-by-default boundaries for every operating role.

Roles is a source-static governance surface. Admin, Manager, Owner, Field, Vendor/Cleaner, and AI Validator rows can be reviewed, but no invite, assignment, grant, mutation, or tenant activation is available.

Selected roleAdmin

Owner approval before real user provisioning or external account changes

Operating area defaultsLong-Term

Compact role preview keeps cross-role visibility readable without widening any permission surface.

Long-TermManager: Full operational rent/resident/lease contextOwner: Published owner summaries onlyField: No rent ledger or resident financial rowsAdmin: Configuration only unless finance permission is explicit
MoneyManager: Operational receivables, payouts, payables, statements, reconciliationOwner: Owner-visible statements, reports, contributions, draws, approved expensesField: Denied before rows renderAdmin: Entitlements and provider status; finance rows require permission
Work and ScheduleManager: All assigned account/workspace operationsOwner: Approved owner-impact summariesField: Assigned work, checklist, timing, evidence onlyAdmin: Role/property access configuration
Messages and AIManager: Drafts, sources, approval stateOwner: Published summaries onlyField: No private messages or AI sources unless assigned and approvedAdmin: AI access rules and integration scopes

Role Matrix

No invitations
RoleDefault ScopeCan SeeDenied By DefaultApproval GateStatus
AdminAccount/workspace configurationSettings, integrations, roles, permissions, entitlement placeholdersOperational finance detail unless explicit finance permission is grantedOwner approval before real user provisioning or external account changesFixture only
ManagerAssigned account/workspace operationsProperties, Schedule, Work, Messages drafts, Inspections, Money operations, Reports draftsCross-account data, production credentials, live payment actionsHuman approval before owner-visible publication, external sends, or paid actionsMVP operator role
OwnerOwner-visible property groupPublished owner statements, owner reports, approved expenses, contributions, drawsTenant ledgers, private resident payments, draft reports, non-owner payablesPublication gate and owner-visible flagSummary-only
FieldAssigned field work onlyAssigned tasks, checklist steps, timing, evidence prompts, approved access contextFinancials, PII, owner statements, payables, platform payouts, rent balancesProperty assignment and task assignmentRestricted
Vendor / CleanerAssigned service work onlyAssigned work order, checklist, evidence prompt, schedule windowCleaner/vendor pay amounts, owner data, resident ledgers, guest private recordsManager assignment and evidence requirementRestricted
AI ValidatorReview-only repo and synthetic fixture contextApproved docs, PRs, synthetic records, review checklistsSecrets, production data, live customer records, external toolsOwner activates validator through GitHub when readyDeferred

Role Defaults By Operating Area

AreaManagerOwnerFieldAdmin
Long-TermFull operational rent/resident/lease contextPublished owner summaries onlyNo rent ledger or resident financial rowsConfiguration only unless finance permission is explicit
MoneyOperational receivables, payouts, payables, statements, reconciliationOwner-visible statements, reports, contributions, draws, approved expensesDenied before rows renderEntitlements and provider status; finance rows require permission
Work and ScheduleAll assigned account/workspace operationsApproved owner-impact summariesAssigned work, checklist, timing, evidence onlyRole/property access configuration
Messages and AIDrafts, sources, approval statePublished summaries onlyNo private messages or AI sources unless assigned and approvedAI access rules and integration scopes

Role Guardrails

Roles are account-scoped, never global tenant bypassesRole assignments derive from active synthetic POC members only; denial tenant members render as zeroAdmin does not automatically bypass financial visibilityFinance visibility requires explicit permission and is not granted by role label aloneOwner role is summary-only until publication gates passField, vendor, cleaner, and inspector roles cannot see money, PII, source rows, owner statements, private messages, resident ledgers, platform payouts, or private contact dataNo auth setup, Supabase writes, database migrations, seed execution, invitations, provider setup, or real-data migrationFuture owner real data must use a separate second tenant after migration, security, and tenant-isolation approvalAI validator is review-only and requires owner activation

Route Closure