Who has what

Restricted This page is the directory's own answer, read from https://id.profuse.ro when the site was built. Cloudflare Access allows it to infra, people and management only; every other page of this handbook is open to everyone in the directory.

Changing anything here means changing the directory, not this page. Roles are given and taken in the directory's own interface — docs/roles.md says why, under “A role's meaning lives here and in code; who holds it is an operation.” A merge request on this repository changes what a role means; it cannot change who holds one.

Roles, and who holds them

One row per role in the catalogue (docs/roles.md, parsed rather than retyped, so the two cannot drift). What each role reaches in each system is on that page; this one only says who is in it.

rolewhat it is forownerholders
infraoperates production: platform / SRE, and the CTOCTOCodrin Popa (codrin)
tech-leadsseniors who merge, release and read production dataCTOCodrin Popa (codrin)
developersbackend, frontend, mobile engineersCTOCodrin Popa (codrin)
qatesters, test automationCTOCodrin Popa (codrin)
productproduct managers, designersCEOCodrin Popa (codrin)
supportL1/L2 support, customer success, implementationhead of customerCodrin Popa (codrin)
financebilling, invoices, payouts, accountingCEOCodrin Popa (codrin)
salesaccount executives, partnerships (affiliate agents)CEOCodrin Popa (codrin)
marketingsite, blog, content, campaignsCEOCodrin Popa (codrin)
peopleHR and administration: onboarding, offboarding, the directory's peopleCEOCodrin Popa (codrin)
managementCEO and whoever needs the whole picture read-onlyCEOCodrin Popa (codrin)

People, and what they hold

The same fact read the other way round: what one person can reach is the union of the rows their roles occupy on the docs/roles.md table.

personroles
Codrin Popa (codrin)infra, tech-leads, developers, qa, product, support, finance, sales, marketing, people, management

Groups outside the catalogue

The directory holds these groups as well. Some are authentik's own; a group that grants something and is not in the catalogue is a finding for the docs/access-review.md review.

groupmembers
authentik Admins1
authentik Agent-Users0
authentik Read-only0
svc-ldap-search1

A person who holds no role at all does not appear anywhere on this page — they are in no group, so no group lists them. The quarterly review reads the directory's user list directly, which is where that person shows up.