Platform
Access to a box Beta
Being in an organisation does not put you on a box. Access is granted per box, per person, with one role, and the box learns about it from a signed list rather than from a request it has to trust.
Custodian roles
| Role | For | On the box |
|---|---|---|
| box admin | Whoever owns the deployment | Projects and environments, keys and rotation, settings, and everything below. |
| developer | Engineers integrating an application | Connect details and keys for their work, the live view, and the trail. |
| box auditor | Internal audit, compliance, an external reviewer | Read the trail and verify. Cannot change keys, settings or projects. |
The auditor role exists so you can hand someone the evidence without handing them the controls. It is the role to give a reviewer who asks to see your audit trail during a security review.
Granting
- An admin adds a person as a custodian of a named box, with one role.
- The platform writes a new version of that box's manifest and signs it.
- The box picks it up on its next pull, within about a minute, and seals
custodian.granted.
The person can now sign in to that box. Nothing was pushed to the box and no inbound connection was made to it; it asked, verified a signature, and acted on what it verified.
Revoking, and how fast it takes effect
Removing a custodian issues a new manifest the same way. Be precise about the timing, because it matters in an incident:
- New sign-ins to that box stop as soon as the platform knows, because the ticket is refused at the platform before it is ever issued.
- An existing box session lasts until the box sees the new manifest, about a minute, and then ends.
- A box that cannot reach the platform keeps honouring the last manifest it verified, and shows its age on screen. This is the trade for a box that keeps working when we are down.
If you need someone out immediately and the box is offline, that is a box-side action, not a platform one.
Leaving the organisation
Do both, in this order:
- Revoke their custodianships, so every box drops them.
- Disable their account, which ends platform sessions at once.
Then rotate any project key they held, since a key is a credential for a machine rather than for a person. See send events.
Every change is on the record
Grants, changes and revocations are config events on the platform's own hash-chained trail, and the box seals its own copy when it acts on a new manifest. Both sides carry the record, which means an argument about who had access in March has an answer that neither side can edit.