Who has what
Restricted This page is the directory's own answer, read from https://id.profuse.ro when the site was built. Cloudflare Access allows it to infra, people and management only; every other page of this handbook is open to everyone in the directory.
Changing anything here means changing the directory, not this page. Roles are
given and taken in the directory's own interface —
docs/roles.md says why, under
“A role's meaning lives here and in code; who holds it is an operation.” A merge request on
this repository changes what a role means; it cannot change who holds one.
Roles, and who holds them
One row per role in the catalogue (docs/roles.md, parsed rather than retyped, so the two cannot drift). What each role reaches in each system is on that page; this one only says who is in it.
| role | what it is for | owner | holders |
|---|---|---|---|
infra | operates production: platform / SRE, and the CTO | CTO | Codrin Popa (codrin) |
tech-leads | seniors who merge, release and read production data | CTO | Codrin Popa (codrin) |
developers | backend, frontend, mobile engineers | CTO | Codrin Popa (codrin) |
qa | testers, test automation | CTO | Codrin Popa (codrin) |
product | product managers, designers | CEO | Codrin Popa (codrin) |
support | L1/L2 support, customer success, implementation | head of customer | Codrin Popa (codrin) |
finance | billing, invoices, payouts, accounting | CEO | Codrin Popa (codrin) |
sales | account executives, partnerships (affiliate agents) | CEO | Codrin Popa (codrin) |
marketing | site, blog, content, campaigns | CEO | Codrin Popa (codrin) |
people | HR and administration: onboarding, offboarding, the directory's people | CEO | Codrin Popa (codrin) |
management | CEO and whoever needs the whole picture read-only | CEO | Codrin Popa (codrin) |
People, and what they hold
The same fact read the other way round: what one person can reach is the union of the rows their roles occupy on the docs/roles.md table.
| person | roles |
|---|---|
Codrin Popa (codrin) | infra, tech-leads, developers, qa, product, support, finance, sales, marketing, people, management |
Groups outside the catalogue
The directory holds these groups as well. Some are authentik's own; a group that grants something and is not in the catalogue is a finding for the docs/access-review.md review.
| group | members |
|---|---|
authentik Admins | 1 |
authentik Agent-Users | 0 |
authentik Read-only | 0 |
svc-ldap-search | 1 |
A person who holds no role at all does not appear anywhere on this page — they are in no group, so no group lists them. The quarterly review reads the directory's user list directly, which is where that person shows up.