Skip to content

Members and roles in the workspace

Room owners manage their team themselves: add members, change roles, and remove members. You do this through the “Room details” icon at the top right of the workspace. Every change produces an evidence record.

The “Members” section in the room details is visible to people who hold the room owner, governance owner, or platform admin role in this room. Platform admins therefore see it only in rooms where they are members themselves. Someone who is only named as a room’s owner but holds the member role there does not see the section. All other members use the room as usual but don’t see the management view.

A member is assigned through their email address or user reference and receives a role. You can assign people who are already a member of a room or have an account in the NomOS sign-in service.

New users are created by the administration. If a person is not in the system yet, contact your platform administration.

Administrators invite people with a time-limited setup link. Invitations require configured email delivery. An accepted send request does not confirm receipt. You can resend pending invitations. Inactive accounts can be deleted after confirmation when no responsibilities remain; historical evidence is retained. You can’t delete your own account, accounts linked through SSO, or service accounts.

Member (member)

Works in the room: asks questions, uses the knowledge, sees the room’s evidence.

Room owner (room_owner)

Runs the room: manages members, subscriptions, and rule exceptions, and decides on proposals, unless another person is named as decision maker for the decision type.

Governance owner (governance_owner)

Owner powers with a governance focus, typical at the organization level. A new installation does not grant this role. It appears in the selection only once it is already granted in the system.

The selection offers room owner, member, and other roles that are already in use in the system. Platform admin (tenant_admin) is deliberately not granted or revoked inside a room. That belongs to the platform level.

Agents appear in the member list but are deliberately read-only here: their lifecycle (creating, pausing, removing) belongs to the agent management. The row links straight there.

The last owner of a room can neither be removed nor demoted, otherwise the room would have no one in charge. First make another person an owner, then switch. Removing yourself is allowed, unless you are the last owner.

Every membership change (add, change role, remove) produces an evidence record that captures who changed whom and how. It is visible in the room’s audit. A change without effect produces no evidence record.

That record carries a governance act: «change_membership», the member as its subject, and the old and new role, for example «member» to «room_owner» when someone is promoted to owner. Adding a member shows only the new role; removing one shows only the previous role. Open «Show evidence» on the run to see it.

Each row shows who manages a membership. “manual” means it was granted here in the room. “via SSO claim” means the membership comes from a mapped groups or roles value in your company’s identity provider (IdP) and is reconciled at sign-in.

SSO rows are deliberately read-only in the room: the customer IdP controls role and membership. Manually granted memberships are never touched. Platform administration manages mappings under “Identity & SSO”. New mappings take effect at the next sign-in or token renewal; changing or deleting one revokes its current grants immediately.