Skip to content

Authorization

Every Hive account has one role. The role controls access consistently across the dashboard and connected clients.

Roles

  • Collaborator is signed in but is outside the organization. Collaborators can view public content, submit Forage items, comment on visible work, and edit items they authored.
  • Member belongs to the organization. Members can also see private content, create projects, domains, and specs, and manage the team's product work.
  • Administrator has every member capability and can manage Operations settings, connected workspaces, model providers, and the audit trail.

At first sign-in, Hive compares the account's email domain with HIVE_ORG_DOMAINS. A match creates a member; a non-match creates a collaborator. When no organization domains are configured, every signed-in account becomes a member.

Changing the configured domains later does not change existing roles.

What each role can do

CapabilityAnonymousCollaboratorMemberAdministrator
View public projects, domains, specs, and dropsyesyesyesyes
Use the mobile application to view visible Forage items, specs, and Dropsnoyesyesyes
Submit Forage itemsnoyesyesyes
Comment on visible Forage items and specsnoyesyesyes
Create Forage items as GitHub issuesnonoyesyes
Start and inspect Flightsnonoyesyes
View private product worknonoyesyes
Create and manage projects, domains, and specsnonoyesyes
Manage Forage intakenononoyes
Manage Slack and model gateway settingsnononoyes
View the audit trailnononoyes

Anonymous access also depends on HIVE_VISIBILITY. A private instance requires sign-in before any dashboard content is shown.

Resource visibility

Projects and domains can be public or private. Specs inherit their project's visibility and can be narrowed to private, but a spec in a private project cannot be made public.

Public feeds and Slack link previews follow the anonymous view. Content that requires a Hive session is not included.

Change an account role

Role management is not yet available in the dashboard. Until it is, role changes require an operator-side maintenance action. Ask the person who runs your Hive instance to promote or demote the account.

Released under the Mozilla Public License 2.0.