PAI RBAC Model for Org Structures

Source artifacts:

  • /home/duane/.claude/PAI/RBAC_SCHEMA.md
  • /home/duane/.claude/PAI/IAM_ARCHITECTURE.md
  • /home/duane/.claude/PAI/config/account-structure.yml
  • /home/duane/.claude/PAI/config/agents.yml
  • /home/duane/.claude/skills/Agents/Structures/

Purpose

PAI already has identity-tier RBAC for humans, engines, agents, systems, secrets, and memory. The new org structures add session-scoped coordination roles such as Guardian, Volunteer, CEO, L1 Service Desk, CISO, and Red Team.

These must not become global security roles. The RBAC model is therefore two-layered:

  1. Identity RBAC: persistent trust tier and baseline capabilities for a UID.
  2. Org-Scoped RBAC: temporary role grants inside a structure/team/session/resource boundary.

Effective access is the intersection of both layers, never their union.

effective_permission =
  identity_baseline(UID)
  ∩ org_role_grant(structure, role)
  ∩ resource_scope(team/session/ticket/asset)
  ∩ active_guardrails(JIT, approval, severity, gate)

Core Entities

EntityKeyNotes
PrincipalUSR-001Duane; only principal accepts risk, spend, destructive ops, and authorization expansions.
Agent / EngineAGT-###Persistent actor identity from agents.yml.
SystemSYS-###Host/node identity from inventory.
Asset / ServiceAST-###Vaultwarden, Authentik, services, devices, protected applications.
AccountACC-###T0/T1/T2 sovereign account from account-structure.yml.
Org SessionORG-{timestamp}-{slug}Runtime instance of Family, Community, Business, IT Department, or InfoSec Org.
Org Role AssignmentORA-{id}Binds one UID to one org role in one org session.
Task / TicketTASK-{id}Unit of work; may be owned by a scoped role.
GrantGRANT-{id}Optional explicit permission grant; JIT, approval, or exception.

Role Layers

Layer 0: Sovereign Tier

Persistent, global tier from PAI RBAC:

TierMembersBaseline
T0 SovereignUSR-001, AGT-001Full system control, RBAC admin, secret rotation, JIT issue/revoke.
T1 PrivilegedAGT-002, AGT-003, AGT-005Allowed production secrets, scoped memory write, agent tasking, JIT request/use.
T2 StandardAGT-004, ephemeral agentsPublic memory read, observe-only unless explicitly delegated.

Layer 1: Structure Lead Roles

These roles may coordinate within their org session but do not acquire global admin power:

StructureLead RoleCoordination Rights
FamilyGuardianAssign chores, call Partner approval for irreversible actions, escalate to principal/IT.
CommunityModeratorFacilitate rough consensus, close decision, route security findings out.
BusinessCEOOwn scope, assign deliverables, report to principal, submit to gates.
IT DepartmentIT ManagerOwn ticket queue, route L1/L2/L3, report estate status.
InfoSec OrgCISOClassify severity, decide mitigate-vs-monitor, report risk to principal.

Layer 2: Functional Org Roles

Functional roles are scoped to an org session and resource set:

Role ClassExamplesAllowed Pattern
ProducerApprentice, Volunteer, Engineer, SysAdmin, L3 EngineerMay modify assigned task resources only if identity tier permits write/exec.
VerifierPartner, Watch, QA, Reviewer, Board, SecurityTriageRead-first; may block closure but not perform producer changes.
OperatorService Desk, SysAdmin, Network Engineer, DBAMay probe and execute runbook-scoped ops; destructive ops require explicit approval.
SecuritySOC T1, Threat Intel, Red Team, IR Commander, GRCEvidence-chain required; Red Team limited to authorized scope; remediation handed to IT.
ArchivistElder, Librarian, HousekeeperMay summarize/write approved session artifacts; cannot expand access.

Layer 3: Universal Social Structures

Family, household, community, civic, tribal/clan, religious, educational, mutual aid, guild, movement, network, and emergency structures are coordination patterns. They map to the same RBAC primitives as business, IT, and InfoSec structures. They do not create new persistent trust tiers.

StructureLead RolePrimary FunctionDefault RBAC Posture
FamilyGuardianCare, safety, schedule, family-task coordination.Task coordination and approval request only.
HouseholdSteward / HousekeeperShared-space maintenance, routines, cleanup.Owned cleanup tasks and session archive only.
CommunityModeratorConsensus, norms, decision closure.Session coordination and decision routing.
CivicClerk / Advocate / OfficialProcedure, representation, public-record discipline.Record, route, and escalate; no privileged infra by title.
Tribal / ClanElder / DelegateContinuity, dispute routing, cultural memory.Read/search/write summary artifacts only.
Religious / SpiritualElder / CaretakerCounsel, ritual, service, sacred memory.Care-task and memory-summary scope only.
EducationalTeacher / MentorAssign learning work and assess progress.Assign/update learning tasks; assessor gate separated.
Mutual AidCoordinatorNeeds matching, distribution, volunteer routing.Create/assign scoped tasks; no forced assignment.
Guild / ProfessionalMaster / ReviewerCraft standards, mentorship, certification.Owned production plus independent review gate.
MovementOrganizer / SpokespersonMobilization, messaging, research.Message/team coordination; publication requires gate.
NetworkHub / BrokerConnection, information routing, reciprocity.Message/read routing; no write authority by default.
EmergencyIncident CommanderTemporary crisis coordination.Active only under declared incident scope and expiry.

Layer 4: Role Archetypes

Every human-readable title should reduce to one or more archetypes before permissions are granted. The archetype decides the permission shape; the title remains display/context.

ArchetypeCommon TitlesAllowed PatternHard Limit
PrincipalDuane, owner, sovereign sponsorAccept risk, expand authorization, approve spend/destructive ops.Only USR-001 or explicit T0 artifact.
CoordinatorGuardian, Moderator, CEO, Product Owner, Platform Owner, Teacher, Organizer, Incident Commander, Agent HandlerAssign, route, close session decisions, request approvals.Cannot exceed identity tier or bypass gates.
ProducerApprentice, Volunteer, Engineer, Student, Responder, Toolsmith, Data Steward, SREUpdate owned tasks and write work evidence.Cannot approve own work.
VerifierPartner, Watch, QA, Reviewer, Assessor, Board, Access Reviewer, Model Evaluator, Design ReviewerRead, challenge, block closure, certify outcome.Cannot perform producer changes in same gate.
OperatorService Desk, SysAdmin, DBA, Logistics Lead, Release Manager, Backup Operator, Change ManagerExecute runbook-scoped operations on assigned assets/tickets.Destructive or undocumented actions require approval.
SecurityCISO, SOC, Red Team, GRC, IR Commander, Security Architect, Vulnerability Manager, Forensics Lead, Privacy StewardTriage, scan authorized scope, preserve evidence, respond.Cannot accept risk unless T0.
ArchivistElder, Librarian, Clerk, Scribe, Housekeeper, Memory Curator, Records Manager, Knowledge ReviewerPreserve knowledge, summaries, decisions, audit trails.Cannot expand access or mutate source facts.
BrokerConnector, Hub, Delegate, Advocate, Spokesperson, Customer AdvocateRoute messages, introductions, requests, and opportunities.Cannot bind others to obligations.
CaregiverParent, caretaker, counselor, support lead, Calendar Steward, Care Plan Coordinator, Document ClerkTrack care tasks, needs, safety checks.No secret/infra/destructive rights by care title.

Responsibility Translation

Responsibilities translate to domain/action/scope permissions. Assign the smallest permission that lets the role complete the job.

ResponsibilityPermission PatternTypical Gate
Care / supporttask:update:owned, memory:write:summaryGuardian or Caregiver review.
Provision / logisticstask:create:team, task:assign:teamCoordinator approval.
Governance / decision closureteam:close:session, approval:approve:sessionIndependent verifier or principal gate.
Culture / memorymemory:write:knowledge, memory:archive:sessionArchivist plus coordinator close.
Education / mentorshiptask:assign:team, task:update:ownedAssessor/reviewer separation.
Defense / safetysecurity:triage:*, security:scan:authorized-scopePrincipal-approved scope for active testing.
Coordinationagent:message:team, team:assign:sessionSession boundary and expiry.
Repair / conflicttask:update:team, approval:deny:sessionPartner/Watch/Moderator review.
Succession / delegationtask:assign:team, memory:write:knowledgeT0 required for RBAC authority transfer.

Responsibility Bundles

Responsibilities are accountability labels, not direct permissions. They make it clear what a role owns while the grants/blocks still determine what the role can do.

BundleExisting ArchetypeExisting Role FitPermission Translation
Platform ownershipCoordinatorCEO, IT Manager, Platform Ownertask:assign:team, team:assign:session, approval:request:*
Reliability / SREProducer or OperatorEngineer, Engineering L3, Respondertask:update:owned, infra:status:asset, infra:runbook:ticket
Release / change coordinationOperatorIT Manager, SysAdmin L2, Release Manager, Change Managerinfra:status:asset, infra:runbook:ticket, approval:request:destructive
Backup / restore assuranceOperator or VerifierDBA L2, Backup Operator, QAinfra:status:database, task:update:ticket, task:close:gate
Access reviewVerifier or SecurityPartner, QA, Access Reviewer, CISOmemory:read:work, task:update:review, security:triage:session
Finding lifecycleSecurityCISO, SOC T1, SecurityTriage, Vulnerability Managersecurity:triage:*, memory:write:evidence, task:update:ticket
Evidence preservation / forensicsSecurityIR Commander, Forensics Lead, Red Teammemory:write:evidence, security:respond:session
Privacy / data boundarySecurity or ArchivistPrivacy Steward, Records Manager, Librarianmemory:read:work, memory:archive:session, approval:request:risk
Memory curationArchivistLibrarian, Memory Curator, Knowledge Reviewermemory:write:summary, memory:write:knowledge, memory:archive:session
Records retentionArchivistClerk, Scribe, Records Managermemory:archive:session, memory:write:summary
Agent work routingCoordinatorAgent Handler, PM, IT Manageragent:message:team, task:assign:team
Prompt / playbook maintenanceProducer or ArchivistToolsmith, Prompt Librarian, Engineermemory:write:work, memory:write:summary
UI / UX / visual designProducer and VerifierDesigner, Artist, UIReviewer, Design Reviewertask:update:owned, memory:write:work, task:update:review, task:close:gate
Model evaluationVerifierQA, Reviewer, Model Evaluatortask:update:review, task:close:gate, memory:read:work
Stakeholder / customer advocacyBroker or VerifierSpokesperson, Customer Advocate, Boardagent:message:team, memory:read:work, approval:deny:session
Personal operationsCaregiver or ArchivistGuardian, Calendar Steward, Document Clerktask:update:owned, memory:write:summary

Archetype Engagement

Engagement decides which archetypes should participate before any org-session role assignment exists. It is advisory until an ORG-* session and scoped ORA-* assignments are created.

task text + structured context signals + requested actions
  -> archetype engagement policy
  -> recommended archetypes and default structure
  -> coordinator creates proposed ORA assignments
  -> org RBAC authorizer accepts or denies scoped actions

Engagement policy path:

  • Example only: ~/.claude/PAI/config/archetype-engagement.example.yml
  • Future live path: ~/.claude/PAI/config/archetype-engagement.yml

Validation probe:

python3 ~/.claude/PAI/Tools/validate-archetype-engagement.py \
  ~/.claude/PAI/config/archetype-engagement.example.yml

Fixture probe:

python3 ~/.claude/PAI/Tools/validate-archetype-engagement.py --fixture-run \
  ~/.claude/PAI/config/archetype-engagement.example.yml

Classification probe:

python3 ~/.claude/PAI/Tools/validate-archetype-engagement.py --json \
  --classify "harden the FunctionsAPI identity route and add validator tests" \
  --context-signals code_change,touches_identity \
  ~/.claude/PAI/config/archetype-engagement.example.yml

The classifier is read-only. It does not grant permissions, create sessions, create ORA-* assignments, issue credentials, or write audit logs. It only emits a dry-run recommendation with trace evidence.

Candidate preferences may name preferred UIDs for an archetype, such as AGT-008 as Cato Reviewer for Verifier/Security review or Forge Worker for Producer implementation. These are routing hints only. The org RBAC authorizer must still check identity tier, session assignment, scope, lifecycle, and guardrails before any permission is effective.

Engagement uses two signal classes:

Signal TypeSourcePurpose
KeywordsUser/task text such as build, identity, backup, archive, notify.Fast conversational routing.
Context signalsStructured flags such as touches_identity, destructive_action, memory_write, external_message.Reliable routing from tools, tickets, and future session creators.

Mandatory pairings preserve gate discipline:

Triggered ArchetypeAdded ArchetypeReason
ProducerVerifierProducer cannot close its own gate.
SecurityVerifierSecurity-sensitive work needs independent review.
OperatorVerifierInfra/runbook work needs an operational check.
BrokerVerifierPublication or external communication needs a gate.

Principal engagement is explicit. It is required when keywords, context, or requested actions imply risk acceptance, destructive operations, spend, global authority, secret rotation, RBAC admin, or sudo-session capability.

Design engagement is handled as capability routing, not a new authority class. UI, UX, art, frontend, visual, accessibility, responsive, theme, palette, and typography triggers engage Producer for creation/implementation and Verifier for UX review, accessibility review, visual regression, and closure gates.

Role Lifecycle

Org-scoped authority must have a lifecycle. A role without lifecycle state is advisory only.

StateMeaningEnforcement
ProposedRole requested but not active.No grants.
ActiveRole assigned inside an org session.Grants usable within scope and tier ceiling.
SuspendedRole paused due to conflict, incident, expiry concern, or review.Deny all mutating actions.
EscalatedRole has requested approval/JIT/incident authority.Await required grant; no implied access.
ClosedSession or role completed.Grants expired; audit retained.
RevokedAssignment removed before normal close.Deny and log future attempts.

Escalation Model

Escalation is explicit and evidence-bound:

  1. Advisory roles may recommend but cannot grant.
  2. Coordinators may request approval but cannot self-approve privileged action.
  3. Verifiers may block closure but cannot mutate the deliverable being verified.
  4. Operators may execute documented runbooks inside asset/ticket scope.
  5. Security roles may classify severity and preserve evidence; risk acceptance stays T0.
  6. Emergency roles expire automatically when the incident closes or the grant expires.

Permission Namespace

Use domain/action/scope permissions. Existing permissions map cleanly into this form.

DomainActionsExamples
memoryread, write, search, archivememory:write:work, memory:read:public
agentspawn, task, message, revoke, observeagent:spawn:team, agent:task:team
teamcreate, delete, assign, closeteam:assign:session
taskcreate, claim, assign, update, closetask:claim:team, task:close:owned
secretlisted, jit, rotate, denysecret:jit:single-use
infrastatus, runbook, manage, destructiveinfra:runbook:asset, infra:destructive:approved
securitytriage, scan, respond, audit, accept-risksecurity:scan:authorized-scope
approvalrequest, approve, denyapproval:request:destructive
budgetread, limit, spendbudget:read:session
rbacread, adminrbac:admin:global
systemstatus, restartsystem:restart:approved

Scope suffixes:

ScopeMeaning
globalAll PAI resources; T0 only by default.
sessionCurrent org session/team only.
teamCurrent team membership and task list.
ownedResources explicitly assigned to the actor.
asset:{AST/SYS}Named service, host, or asset.
ticket:{id}One IT/security ticket.
authorized-scopeExplicit principal-approved security test scope.

Structure Role Grants

Family

RoleGrantsBlocks
Guardianteam:assign:session, task:create:team, agent:message:team, approval:request:destructiveCannot bypass Partner/principal approval for irreversible actions.
Partnerapproval:approve:session, task:update:team, memory:read:workCannot execute destructive action directly.
Eldermemory:read:work, memory:search:work, memory:write:summaryNo secret, infra, or destructive rights.
Apprenticetask:update:owned, memory:write:workOwn task only; no approval authority.
Housekeepertask:close:owned, memory:archive:sessionCleanup only; no deletion outside session temp artifacts.

Community

RoleGrantsBlocks
Moderatorteam:close:session, task:update:team, agent:message:teamCannot assign owned work except to break deadlock.
Organizertask:create:team, task:update:teamCreates unowned work; cannot force volunteers.
Volunteertask:claim:team, task:update:owned, memory:write:workCannot write final knowledge artifacts directly.
Librarianmemory:write:knowledge, memory:archive:sessionWrites curated findings only after Moderator close.
Watchmemory:read:work, task:update:teamRead/cross-check only; cannot own findings.

Household

RoleGrantsBlocks
Stewardtask:create:team, task:assign:team, memory:write:summaryCannot approve destructive household/infra changes.
Housematetask:claim:team, task:update:ownedOwn tasks only; no assignment authority.
Maintainerinfra:status:asset, infra:runbook:ticket, task:update:ticketRunbook-scoped only; repairs that change infra escalate to IT.
Guestmemory:read:public, task:update:ownedTemporary, narrow task scope only.

Education / Guild

RoleGrantsBlocks
Teacher / Mentortask:create:team, task:assign:team, memory:write:workCannot certify own curriculum or final assessment.
Student / Apprenticetask:update:owned, memory:write:workCannot close assessment gate.
Assessor / Master Reviewertask:close:gate, task:update:review, memory:read:workCannot rewrite submitted work while acting as gate.
Scribememory:write:summary, memory:archive:sessionCannot alter source records.

Mutual Aid / Movement / Network

RoleGrantsBlocks
Coordinatortask:create:team, task:assign:team, agent:message:teamCannot force volunteer ownership or expand scope.
Volunteertask:claim:team, task:update:owned, memory:write:workCannot publish final artifacts directly.
Spokespersonagent:message:team, memory:read:work, memory:write:summaryExternal publication requires gate approval.
Broker / Hubagent:message:team, memory:read:publicCannot bind principals, teams, or assets to obligations.
Researchermemory:write:work, task:update:ownedExternal content remains untrusted until reviewed.

Emergency / Crisis

RoleGrantsBlocks
Incident Commandertask:assign:incident, security:respond:sev1-2, approval:request:destructiveActive only during declared incident; cannot accept risk.
Respondertask:update:owned, infra:runbook:ticket, memory:write:evidenceNo undocumented or destructive action without approval.
Communications Leadagent:message:team, memory:write:summaryCannot issue technical authority or risk acceptance.
Logistics Leadtask:create:team, task:assign:team, budget:read:sessionSpend requires principal approval.

Business

RoleGrantsBlocks
CEOteam:assign:session, task:assign:team, approval:request:*, budget:read:sessionCannot overrule failed QA/Board gates.
COOtask:assign:team, task:update:team, agent:message:teamNo scope changes without CEO.
PMtask:create:team, task:update:requirements, memory:write:workRead-only regarding implementation.
Engineertask:update:owned, memory:write:work, infra:status:ownedNo production deploy/destructive ops without approval.
QAtask:close:gate, memory:read:work, infra:status:ownedBlocks closure; does not implement fixes.
Reviewertask:update:review, memory:read:workRead-only on diffs.
Boardtask:close:gate, approval:deny:sessionFinal gate; cannot directly modify deliverables.

IT Department

RoleGrantsBlocks
IT Managertask:assign:team, team:close:session, infra:status:asset, approval:request:destructiveCannot accept security risk.
Service Desk L1infra:status:asset, infra:runbook:ticket, task:update:ticketDocumented runbooks only; undocumented work escalates.
SysAdmin L2infra:status:asset, infra:manage:asset, memory:write:runbookDestructive ops require principal approval.
Network Eng L2infra:status:network, infra:manage:network, memory:write:runbookRoute/firewall destructive changes require approval.
DBA L2infra:status:database, infra:manage:database, memory:write:runbookDrop/truncate/migrate require approval and backup probe.
Engineering L3task:update:owned, memory:write:work, infra:manage:approved-assetArchitecture changes become Business project scope.

InfoSec Org

RoleGrantsBlocks
CISOsecurity:triage:session, security:respond:session, approval:request:risk, task:assign:teamCannot accept risk for Duane.
SOC T1security:triage:signal, memory:write:evidence, task:update:ticketNo remediation execution.
SecurityTriagesecurity:triage:finding, memory:write:evidenceSkill invocation only; no direct infra modification.
Threat Intelmemory:write:intel, security:triage:contextExternal content treated as untrusted.
Red Teamsecurity:scan:authorized-scope, memory:write:evidenceNo out-of-scope testing; no patching.
IR Commandersecurity:respond:sev1-2, task:assign:incidentOnly active for SEV1/SEV2 or explicit activation.
GRCsecurity:audit:policy, memory:write:evidenceAudits coverage; does not implement controls.

Inheritance and Deny Rules

  1. Identity ceiling: an org role cannot grant more than the actor’s persistent tier permits.
  2. Session boundary: org grants expire when the team/session closes.
  3. Resource binding: producer roles operate only on owned tasks/assets.
  4. Gate separation: producer and verifier roles cannot close the same deliverable without an independent gate role.
  5. Red/blue separation: Red Team cannot remediate; blue/IT cannot retroactively authorize a red probe.
  6. Principal-only decisions: risk acceptance, spend, authorization expansion, and destructive operations require Duane or an explicit T0 approval artifact.
  7. Deny beats allow: deny from guardrail, missing approval, expired JIT, severity stop, or out-of-scope asset overrides any role grant.
  8. No global role leakage: Guardian/CEO/CISO/IT Manager/Moderator are org-session roles, not Authentik groups.

Data Schema

Minimum YAML registry shape:

org_sessions:
  - id: ORG-20260614-rbac-example
    structure: business
    team_name: venture-example
    created_by: AGT-001
    status: active
    lifecycle_state: active
    resource_scope:
      memory_paths:
        - MEMORY/WORK/20260614-rbac-example/
      assets: []
      repos: []
    assignments:
      - id: ORA-001
        uid: AGT-003
        role: Engineer
        structure: business
        team_name: venture-example
        task_scope:
          - TASK-001
        grants:
          - task:update:owned
          - memory:write:work
        lifecycle_state: active
        expires_at: 2026-06-14T23:59:59Z
    approvals:
      - id: GRANT-001
        type: destructive-op
        requested_by: AGT-001
        approved_by: USR-001
        scope: asset:SYS-001
        expires_at: 2026-06-14T18:00:00Z

Recommended storage:

  • Canonical definitions: ~/.claude/PAI/config/org-rbac.yml
  • Runtime sessions root: MEMORY/STATE/org-sessions/
  • Active runtime sessions: MEMORY/STATE/org-sessions/active/{ORG_ID}.yml
  • Closed session archive: MEMORY/STATE/org-sessions/closed/{ORG_ID}.yml
  • Revoked/security-stopped sessions: MEMORY/STATE/org-sessions/revoked/{ORG_ID}.yml
  • Non-authoritative examples: MEMORY/STATE/org-sessions/examples/ORG-EXAMPLE-{structure}.yml
  • Audit log: MEMORY/SECURITY/org-rbac-audit.jsonl

Files must not be stored directly under MEMORY/STATE/org-sessions/ except README.md and directory placeholders. Moving a session file between active/, closed/, and revoked/ is a lifecycle state transition; use Tools/org-session-manager.py for normal lifecycle changes.

Enforcement Contract

The markdown model is the human source. Runtime enforcement should compile from a structured registry with four tables:

  1. structures: known structure IDs, allowed roles, default lifecycle policy.
  2. archetypes: reusable permission and hard-limit templates.
  3. role_bindings: structure-specific title to archetype mappings.
  4. constraints: global deny, separation-of-duty, lifecycle, approval, and expiry rules.

Example contract path:

  • Example only: ~/.claude/PAI/config/org-rbac.example.yml
  • Future live path: ~/.claude/PAI/config/org-rbac.yml

Validation probe:

python3 ~/.claude/PAI/Tools/validate-org-rbac.py ~/.claude/PAI/config/org-rbac.example.yml

Fixture probe:

python3 ~/.claude/PAI/Tools/validate-org-rbac.py --fixture-run ~/.claude/PAI/config/org-rbac.example.yml

Dry-run authorization probe:

python3 ~/.claude/PAI/Tools/validate-org-rbac.py --authorize \
  --actor-uid AGT-003 \
  --structure business \
  --role Engineer \
  --action task:update:owned \
  --resource TASK-001 \
  ~/.claude/PAI/config/org-rbac.example.yml

Session dry-run authorization probe:

python3 ~/.claude/PAI/Tools/validate-org-rbac.py --authorize \
  --actor-uid AGT-003 \
  --action task:update:owned \
  --resource TASK-001 \
  --session-file ~/.claude/PAI/MEMORY/STATE/org-sessions/examples/ORG-EXAMPLE-business.yml \
  ~/.claude/PAI/config/org-rbac.example.yml

Audit-preview probe:

python3 ~/.claude/PAI/Tools/validate-org-rbac.py --json --audit-preview --authorize \
  --actor-uid AGT-003 \
  --action task:update:owned \
  --resource TASK-001 \
  --session-file ~/.claude/PAI/MEMORY/STATE/org-sessions/examples/ORG-EXAMPLE-business.yml \
  ~/.claude/PAI/config/org-rbac.example.yml

Self-test gate:

python3 ~/.claude/PAI/Tools/validate-org-rbac.py --self-test ~/.claude/PAI/config/org-rbac.example.yml

Advisory agent/job route:

python3 ~/.claude/PAI/Tools/agent-job-routing.py \
  --task "Fix failing GitHub Actions CI for a Cloudflare Worker PR" \
  --resource TASK-001 \
  --json

The router recommends structure, role, engine, skills, an RBAC request draft, and org-session-manager.py command drafts. It does not create sessions, assign authority, or bypass validation.

Switchboard movement preflight:

python3 ~/.claude/PAI/Tools/switchboard-rbac-router.py \
  --actor-uid AGT-001 \
  --target execute \
  --resource PLAN-001 \
  --session ORG-YYYYMMDD-HHMMSS-session \
  --role Moderator \
  --json

Switchboard dispatches and Kanban moves must stop on a deny verdict. The preflight checks active org-session state through validate-org-rbac.py; it does not create sessions or grant authority.

Live enforcement point:

python3 ~/.claude/PAI/Tools/org-rbac-live-enforcer.py \
  --actor-uid AGT-003 \
  --action task:update:owned \
  --resource TASK-001 \
  --session ORG-YYYYMMDD-HHMMSS-session \
  --role Engineer \
  --json

org-rbac-live-enforcer.py is the runtime guard boundary for org-scoped actions. It resolves the session, calls validate-org-rbac.py, returns an effective allow/deny verdict, and appends MEMORY/SECURITY/org-rbac-live-enforcement.jsonl. Principal/T0 override is explicit and audited:

python3 ~/.claude/PAI/Tools/org-rbac-live-enforcer.py \
  --actor-uid AGT-003 \
  --action task:close:gate \
  --resource TASK-001 \
  --session ORG-YYYYMMDD-HHMMSS-session \
  --role Engineer \
  --override \
  --override-by USR-001 \
  --override-reason "principal accepted closure risk" \
  --json

Overrides change only the effective verdict. The validator verdict and reason remain in the audit record.

JSON request probe:

python3 ~/.claude/PAI/Tools/validate-org-rbac.py \
  --request-json ~/.claude/PAI/config/examples/org-rbac-request-allow.json \
  ~/.claude/PAI/config/org-rbac.example.yml

Stdin request probe:

cat ~/.claude/PAI/config/examples/org-rbac-request-allow.json | \
  python3 ~/.claude/PAI/Tools/validate-org-rbac.py \
    --request-json - \
    ~/.claude/PAI/config/org-rbac.example.yml

The validator and dry-run authorizer are read-only. They do not issue credentials, mutate org sessions, write audit events, or promote the example contract/session to live enforcement. --audit-preview emits the future audit event shape in stdout only; it must not append to MEMORY/SECURITY/org-rbac-audit.jsonl. A dry-run allow is diagnostic only; live enforcement still requires guardrail integration.

Canonical Keys

KeyRequiredMeaning
schema_versionyesContract version; incompatible changes increment major version.
structures[].idyesStable lowercase structure ID such as family, business, emergency.
structures[].roles[].titleyesHuman-readable title, not an Authentik group.
structures[].roles[].archetypeyesOne of the registered archetypes.
structures[].roles[].grantsyesAllow-list of domain/action/scope permissions.
structures[].roles[].blocksyesExplicit denies or non-authorities for that title.
structures[].roles[].responsibilitiesnoAccountability labels for planning and audit; not direct permission grants.
structures[].roles[].requiresnoRequired gate, approval, declared incident, or scope proof.
structures[].roles[].max_lifecyclenoHighest lifecycle state this role can enter without T0.
constraints[].idyesStable constraint ID for audit and test fixtures.
constraints[].effectyesdeny, require_approval, require_separation, or require_scope.

Grant Compilation

Compile grants in this order:

compiled_role(actor, assignment) =
  identity_tier_ceiling(actor.uid)
  ∩ archetype_template(assignment.archetype)
  ∩ structure_role_grants(assignment.structure, assignment.role)
  ∩ assignment_resource_scope(assignment)
  ∩ active_explicit_grants(assignment)

The compiler must reject any role binding that:

  1. References an unknown archetype.
  2. Uses a permission outside the known namespace.
  3. Grants global scope to non-T0 identities.
  4. Grants secret:*, rbac:admin, security:accept-risk, budget:spend, or infra:destructive without explicit T0 approval.
  5. Has no blocks entry for authority-sensitive roles.
  6. Omits expiry for emergency, security, JIT, or external participant roles.

Deny Precedence

Deny rules evaluate before allows. The first matching deny should be logged with its constraint ID.

OrderDeny SourceExample
1Identity revoked or inactiveUID disabled, DID revoked, expired session credential.
2Lifecycle not activeProposed, suspended, closed, or revoked assignment.
3Scope mismatchActor assigned to TASK-001 attempts TASK-002.
4Missing principal approvalDestructive, spend, risk acceptance, authority expansion.
5Separation-of-duty violationProducer tries to close own QA gate.
6Red/blue conflictRed Team tries to remediate finding it produced.
7Expired JIT or explicit grantGrant TTL elapsed or single-use token consumed.
8Guardrail or severity stopSafety hook, policy deny, SEV escalation freeze.

Constraint Types

Represent guardrails as data, not prose:

ConstraintRequired FieldsExample
principal_onlyactions, approver_uidinfra:destructive:* requires USR-001.
separation_of_dutyproducer_archetypes, verifier_archetypes, same_resourceProducer cannot close same deliverable.
red_blue_separationred_roles, blue_actionsRed Team cannot remediate.
lifecycle_gateallowed_states, mutating_actionsMutations require active.
scope_requiredactions, scope_fieldsSecurity scans need authorized_scope.
expiry_requiredroles, max_ttl_minutesEmergency roles expire.
publication_gateroles, approver_archetypesSpokesperson drafts; verifier publishes.

Lifecycle Transitions

Lifecycle transitions are also authorization events:

FromToRequired Authority
noneproposedCoordinator or T0.
proposedactiveCoordinator plus identity-tier eligibility.
activesuspendedCoordinator, Verifier, Security, or T0.
suspendedactiveOriginal coordinator plus verifier or T0.
activeescalatedExplicit approval/JIT/incident request.
escalatedactiveApproval resolved or escalation revoked.
activeclosedCoordinator or session close gate.
anyrevokedT0, security stop, or expired identity credential.

Authorization Fixtures

Minimum fixture cases for an implementation test suite:

CaseExpected
business.engineer.update_owned_taskallow
business.engineer.close_qa_gate_same_taskdeny: separation_of_duty
family.guardian.assign_taskallow
family.guardian.execute_destructive_infradeny: principal_only
community.volunteer.write_final_knowledgedeny: publication_or_archivist_gate
education.student.close_assessmentdeny: separation_of_duty
movement.spokesperson.publish_without_gatedeny: publication_gate
emergency.commander.assign_after_expirydeny: expired_assignment
infosec.red_team.scan_without_scopedeny: missing_authorized_scope
infosec.red_team.remediate_own_findingdeny: red_blue_separation
it.l1.undocumented_destructive_opdeny: principal_only
t2.external.secret_jit_requestdeny: identity_ceiling

Enforcement Algorithm

authorize(actor_uid, action, resource, context):
  1. Load actor from agents.yml / identity registry.
  2. Load identity tier from RBAC_SCHEMA.md-backed config.
  3. Load active org session and role assignments.
  4. Reject if no active assignment for org-scoped action.
  5. Reject if assignment lifecycle is not active.
  6. Normalize title to role archetype and grants.
  7. Reject if action exceeds identity baseline.
  8. Reject if action is outside assignment resource scope.
  9. Reject if a guardrail applies and required approval/JIT/SEV is absent.
  10. Reject if separation-of-duty rule is violated.
  11. Emit audit event with UID, session, role, archetype, action, resource, verdict.
  12. Permit.

Audit event:

{
  "ts": "2026-06-14T16:31:27Z",
  "actor_uid": "AGT-003",
  "identity_tier": "T1",
  "org_session": "ORG-20260614-rbac-example",
  "structure": "business",
  "org_role": "Engineer",
  "role_archetype": "Producer",
  "action": "task:update:owned",
  "resource": "TASK-001",
  "verdict": "allow",
  "reason": "identity_baseline_and_org_scope_match"
}

Migration Path

  1. Convert the five structure YAML contracts into a generated org-rbac.yml role-grant registry.
  2. Extend team/session creation to write MEMORY/STATE/org-sessions/active/{ORG_ID}.yml.
  3. Add an authorization helper used by TeamCreate, TaskCreate/TaskUpdate, SendMessage, Skill invocation, and shell/secret guardrails.
  4. Add role-archetype normalization so titles map to Coordinator, Producer, Verifier, Operator, Security, Archivist, Broker, or Caregiver before grants are evaluated.
  5. Add lifecycle enforcement for proposed, active, suspended, escalated, closed, and revoked assignments.
  6. Add separation-of-duty checks for Business gates, Education/Guild assessment gates, and InfoSec red/blue boundaries.
  7. Add ticket/asset scoped checks for IT Department operations and Emergency response.
  8. Add an audit command that verifies every org role has grants, blocks, scope, lifecycle, and expiry.

Verification Probes

Required probes before treating this as enforced:

ProbeExpected
Parse all five structure contractsEvery role has kind, binding, required, and valid structure ID.
Generate org-rbac.ymlAll roles appear exactly once per structure.
Validate org-rbac.example.ymlvalidate-org-rbac.py exits 0 with zero errors and expected fixture verdicts.
Dry-run allow decisionBusiness Engineer task:update:owned returns allow:allowed with compiled grants.
Dry-run deny decisionFamily Guardian infra:destructive:asset returns deny:principal_only_authority.
Session dry-run allow decisionExample session assignment resolves AGT-003 as Engineer for TASK-001.
Session dry-run scope denyExample session assignment denies AGT-003 access to unassigned TASK-002.
Audit-preview dry-run--audit-preview emits dry_run: true, verdict, reason, actor, session, role, action, resource, and trace.
Self-test gate--self-test passes validation, fixtures, session allow/deny, and audit-preview shape checks.
JSON request interface--request-json accepts file/stdin request objects and returns a JSON decision.
Spawn sample Business sessionEngineer can update owned task; cannot close QA gate.
Spawn sample Community sessionVolunteer can claim unowned task; cannot write final Knowledge artifact.
Spawn sample Family/Household sessionGuardian/Steward can assign care or cleanup tasks; cannot execute destructive infra changes.
Spawn sample Education/Guild sessionStudent can update owned work; Assessor can close gate; same actor cannot do both for one deliverable.
Spawn sample Movement/Network sessionSpokesperson can draft summary; publication denied without gate approval.
Spawn sample Emergency sessionIncident Commander can assign incident tasks only while lifecycle is active and incident scope is declared.
Spawn sample IT sessionL1 can runbook-resolve; cannot execute undocumented destructive op.
Spawn sample InfoSec sessionRed Team scan denied without authorized-scope; remediation denied.
Expiry checkRole grant denied after session close or expires_at.
Lifecycle checkProposed, suspended, closed, and revoked role assignments deny mutating actions.
Audit checkEvery allow/deny writes UID, role, action, resource, verdict.

Anti-Model

Do not create Authentik groups named pai-ceo, pai-ciso, pai-guardian, pai-volunteer, or similar. Those are coordination roles, not identity-trust roles. Authentik should continue to hold stable IAM groups such as pai-admin, pai-agent-privileged, and pai-agent-standard; org roles belong in session state and audit logs.