TalentOS Help
Governance & privacy

Who can do what

Owner, admin, manager, member, and the rules that decide what a Talent is allowed to do on your behalf.

Work out which of the four seats each person needs, and you are done. TalentOS has no fine grained permission editor to configure, on purpose.

The rule underneath all of it: a seat gates authority, never participation. An admin is not a supervisor account with a different product. Everyone has their own Talent, their own connected tools, their own memory, and their own work. Higher seats simply add governance on top.

The four seats

Member. The everyday seat and the whole product. A member has their own Talent, connects their own apps, writes Routines and Skills, keeps their own memory, publishes to the Marketplace, and adopts from it. Every member sits in a department.

Admin. A member, plus governance of the workspace. Admins invite and remove members, create and archive departments, move people between them, assign manager seats, hold workspace settings, and read billing and workspace spend.

Manager. Not a role. A department scoped grant that sits on top of whatever someone already is, so a member or an admin can hold one. It adds a Manager group in the sidebar for the department they run, where they curate its shared memory. One manager per department.

Owner. Exactly one per workspace, and always an admin as well. The owner holds money and admin appointment. See What only the owner can do.

Pick the right one

You want them toGive them
Do the work, with their own Talent and toolsMember
Look after one department's shared knowledgeMember plus a manager seat
Invite people and run departments and settingsAdmin
Change the plan or the cardThey already need to be the owner

Give admin to the people who actually administer, usually one or two in a team of 20. It buys them nothing extra as a practitioner, and it does not let them read anyone's work.

What a Talent may do

A Talent holds capabilities, never a role. It is a bounded subset of the authority of the person who owns it, and it can never exceed them.

  • It acts as its owner, with their connected accounts. Priya's Talent reads Priya's email because Priya connected it, and it has no path to yours.
  • It cannot publish work to the department or the company on its own. Widening an audience is a decision a person makes in the console.
  • Consequential actions carry an approval step. See Approve what your Talent does.
  • Talking to your Talent from a connected messaging channel gives it exactly the same authority it has in the web console, and no more.

A worked example

Priya runs Client Services but does not administer the workspace. Give her a member role plus the Client Services manager seat. She can use her own Talent, connect her own tools, and curate that department's shared memory. She cannot invite a new teammate or change billing, so an admin handles the invitation and the owner handles the plan.

What to check

Someone is missing a section of the sidebar. Sections are absent rather than disabled when a seat does not include them. Check their row in Team, Directory, and confirm the seat, then ask them to reload.

An admin cannot change a plan. Correct. Billing writes are owner only.

A control is visible but refuses. Every rule here is enforced on the server, not just in the interface, so the refusal is the real answer. The message names which seat the action needs.

On this page