Roles and permissions
What administrators, office managers and members can do, and what stays private to each person.
Orlok has two roles in the installation, administrator and member. Inside each office, a member is either a manager or a plain member. Virtual colleagues have no role of their own: they work for one person, with that person's rights.
The roles
- Administrator: manages the installation from the Admin area and works in every office through the role. Administrators belong to no office: none are ticked on their person, and a member promoted to administrator leaves the offices they had.
- Office manager: a member who also edits and reviews the wiki of that office.
- Member: works in the offices they belong to, with their own colleagues.
Someone can be a manager in one office and a plain member in another. The People page explains how to set roles and offices.
Who can do what
| Action | Administrator | Office manager | Member |
|---|---|---|---|
| Create their own virtual colleagues, with a granted profile | ✓ | ✓ | ✓ |
| Store their own credentials | ✓ | ✓ | ✓ |
| Read and search the office wiki, see its graph, status and log | ✓ all offices | ✓ | ✓ |
| Save an answer or a proposal from their conversations to the wiki | ✓ | ✓ | ✓ |
| Create, edit, delete and restore wiki pages | ✓ | ✓ | — |
| Write the wiki's purpose and the search synonyms | ✓ | ✓ | — |
| Close review items and run checks on the wiki | ✓ | ✓ | — |
| Upload and import documents and notes into the wiki | ✓ | ✓ | — |
| Empty an office's wiki | ✓ | — | — |
| Manage models, colleague profiles, email, offices, people and hosts | ✓ | — | — |
| Manage the office MCP servers | ✓ | — | — |
| Read the office audit and the installation log | ✓ | — | — |
| Turn off a person's "always allowed" command type | ✓ | — | — |
What stays private
Some things belong to one person, and administrators do not see them either:
- Virtual colleagues and their conversations. Each person sees only their own colleagues and the conversations with them.
- Credentials. Nobody else's credentials are ever listed, changed or tested, administrators included. Credentials are stored encrypted and handed only to the runner.
- Approvals. Only the person a command runs for can approve it, refuse it or stop its plan.
- Proposals for the wiki that a colleague makes in a conversation: only that person sees them, and decides whether to save each one.
What a colleague saves to the wiki is no longer private: the office wiki is read by everyone in the office.
Administrators manage, they do not impersonate. An administrator grants profiles, adds hosts and can turn off a person's approved command types, but cannot open someone else's conversations, approve their commands or use their credentials. When an administrator disables a person, that person's sessions end at once and their credentials are deleted.
A colleague never has more rights than its person
A virtual colleague acts for the person who created it, and only within:
- the profile an administrator granted that person: the model, and how the colleague may run commands (see Modes);
- the offices of that person: the colleague reads and updates only their wikis;
- the person's credentials: the colleague reaches only the hosts where the person has one, and acts there as that person. It cannot see the credential or pick another.
If an administrator takes a profile away, the colleagues that used it wait for their person to choose another one.