Departments and permissions

Your org chart, enforced branch by branch

Two levels of authority: each person's role in the company and their seat in each department. An area lead administers their branch and everything hanging off it. A contributor sees exactly their own, with no access list for anybody to maintain by hand.

  • Five roles
  • Inherited downward
  • No privilege escalation

Two levels that combine

The company role says what a person can do in general. The department seat says what they can do in that particular branch. A department is administered by whoever owns or administers the company, and also by whoever holds a lead seat in that department or in any of its ancestors. Authority travels down the tree and never up: leading Sales grants nothing in Finance.

  • On login, each person gets exactly the departments they can work in
  • Nobody maintains an access list: it is derived from the org chart that already exists
department tree as Ana sees it, lead of Executive
  • Constructora Andes
  • Executive lead: Ana
  • Finance inherited from Executive
  • Legal inherited from Executive
  • Sales lead: Marco
  • Proposals
  • After-sales contributor: Sofía
  • Operations
Ana administers her whole branch. Sales and Operations do not appear for her.

A tree with no depth limit, and a folder that answers to it

A department is both a workspace and a folder in the vault, with one canonical path stored once. The database and the disk cannot disagree, because there are no two paths to keep in sync. A department becoming its own ancestor is impossible: the tree is walked with a depth guard and a visited-node set.

  • Renaming a department rewrites the title of its main note and nothing else: the folder does not move, so the agent context does not break
  • Its own emoji, drag to reorder, and archive without deleting
the tree and the disk one single path
  • Sales sales/
  • Proposals sales/proposals/
  • Tenders sales/proposals/tenders/
  • After-sales sales/after-sales/
  • Renamed to "Commercial" the folder is still sales/
The visible name changes; the id and the path on disk do not. That is why a rename breaks nothing.

Every department arrives assembled

Creating a department writes its folders on disk and its main note, with the tree context in the metadata and three live sections: tasks, memory and files. The tables in that note are queries over the real notes in the folder, so they update themselves when somebody adds something. The main note cannot be deleted, moved or renamed, because it is what the agent reads to know where it is standing.

sales/sales.md Main note

---

title: Sales

parent: Constructora Andes

children: [Proposals, After-sales]

---

## Tasks

live query over sales/tasks/

## Memory

what the agent learned, dated and sourced

## Files

live query over sales/files/

You can edit it by hand. You cannot delete, move or rename it.

Nobody promotes themselves

An administrator only touches roles strictly below their own, and the invitation form offers only the roles that person is allowed to assign, so the rule does not depend on anybody remembering it. The last active owner cannot be demoted or removed, so a company is never left with nobody to administer it. Adding somebody who already has an account reuses their identity; if they do not, one is created with a single-use temporary password.

who can assign what
Action OwnerAdministratorArea lead
Appoint an administrator Yes No No
Appoint an area lead Yes Yes No
Add a contributor to their branch Yes Yes Yes
Remove the last owner No No No

One identity, several companies

An email address is unique across the platform. If you work with two companies you log in once and switch with a click: no second account and no second password. Each company sees only its own, and switching carries nothing over from the previous one, not open notes, not conversations, not permissions.

  • Useful for an accountant, a legal adviser or a partner serving several companies
  • Logging out revokes every live session that person has, immediately
switch company ana@estudio.ec
  • Constructora Andes active
  • Andes Inmobiliaria
  • Fundación Andes
One account, three companies, no data shared between them.

What it does not do yet

The roles are five and they are fixed

You choose between owner, administrator, area lead, contributor and reader, then tune with each person's seat in each department and with per-file permissions. What you cannot do is define a role of your own or field-level permissions, the kind where somebody sees the contract but not the amount. For most companies of ten to a hundred and fifty people that is plenty; if your case needs finer grain, it is worth saying so before you start.

Start free. Pay when it earns it.

Starter credit so you can try it against your own real documentation. No card and no sales call. If it works, you pick a plan.

  • Starter credit on the house
  • No credit card
  • Every feature included