Platform team directory

The roster of everyone who works for the agency, what each of them can reach, and who used to have access but does not any more.

What it is

One page that merges the code-defined owners with the invited staff rows, shows each person's role, invite state, last seen, and lets an admin invite, change a role, revoke with a mandatory reason, or reinstate. Sub-account owners never appear here — the vocabulary is enforced on purpose.

Also called: staff list · who works here · invite staff · revoke access · vendor employee list

See it
Platform team directory
CustomerBuildingAmountStatus
Ivy BrubakerEquipment Storage$16,590Approved
Ivy Brubaker40×64 Shop$13,550Approved
Marlin Hoover30×40 Garage$5,000Open
Ronan Petsch30×40 Garage$2,150Draft
Gideon Alt40×64 Shop$13,550Draft
The roster with role filter chips, one card showing 'Invite pending' and a former-staff card showing 'Access revoked' plus the reason. Sample data — no customer information appears here.
How it works
  1. 1Owners come from source code and render read-only, with no controls at all.
  2. 2Staff are invited by email with a role; the invitation lands them on the panel once accepted.
  3. 3Status chips say what the state MEANS — 'Invite pending', 'Listed - no access' — rather than a bare word that reads as done.
  4. 4Role changes save inline; revoking opens a form because a reason is mandatory.
  5. 5Filters by role, status and search answer 'who holds admin?', which a card list alone cannot.
  6. 6The owner cannot be invited, demoted, revoked or written as a staff row — checked at three independent layers.
Why we built it

Straight from the page header: 'It exists because those things were previously only knowable by reading an environment variable, and when that variable drifted, a sub-account owner silently held administrative access to every other customer for weeks.' The invite-link rule carries its own bug code —: the first invitation ever sent carried a localhost URL because it came from the request origin on a dev machine.

The problem
  • Access was configured in an env var that nobody could read or audit.
  • Revocations happened without a recorded reason, so reviews had nothing to review.
  • Invitation links could point at a developer's laptop.
Sound familiar?
What you get
Access reviews take a minute and produce a record.
Every grant and every revocation has an actor, a time and a reason.
The owner cannot be accidentally locked out of his own platform.
What's inside

See it on your own jobs

Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.

or keep browsing features →