Access control

Company directory

Everyone in the control plane and what their capability token actually grants — computed with effectiveCapability(), the same caps(child) ⊆ caps(parent) fold the host enforces. Token secrets never leave the host; only the computed scope shows.

Monica (CFO)

human · finance

stripe/finance_privatequery · readcreditsdiscount_tieremployee_salarygrossnetperiodteam

Owns 1 agent

Monica (CFO)'s agent

agent:cfo/1

Delegate →
stripe/spend_by_teamquery · readgrossnetperiodteam

Richard (CEO)

human · engineering

stripe/spend_by_teamquery · readgrossnetperiodteam

Owns 1 agent

Richard (CEO)'s agent

agent:cto/1

Delegate →
stripe/spend_by_teamquery · readgrossnetperiodteam

Dinesh (CTO)

human · engineering

stripe/spend_by_teamquery · readgrossnetperiodteamteam{eng, ops}

Owns 1 agent

Dinesh (CTO)'s agent

agent:eng/1

Delegate →
stripe/spend_by_teamquery · readgrossnetperiodteamteam{eng}

Read-only · membership-rooted. No data authority is mintable here — delegation narrows a token you already hold, and the CFO root is the only minter of finance_private.