Governance & Permissions
Governance in Computtite covers how access and actions are controlled across a shared workspace. This is a cloud mode feature — local mode workspaces have a single user with full access and no multi-user controls. In cloud mode, every workspace member has a role that determines their base capabilities, optionally modified by a permission profile that can further restrict those capabilities.
Workspace Roles
Every member invited to a cloud workspace is assigned one of four roles. Roles form a strict hierarchy — Owner > Admin > Member > Viewer.
| Permission | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| View assets | ✓ | ✓ | ✓ | ✓ |
| Export reports | ✓ | ✓ | ✓ | ✓ |
| Create assets | ✓ | ✓ | ✓ | ✗ |
| Edit assets | ✓ | ✓ | ✓ | ✗ |
| Sync data | ✓ | ✓ | ✓ | ✗ |
| Delete assets | ✓ | ✓ | ✗ | ✗ |
| Manage members | ✓ | ✓ | ✗ | ✗ |
| Edit workspace settings | ✓ | ✓ | ✗ | ✗ |
| Transfer ownership | ✓ | ✗ | ✗ | ✗ |
- Owner: Full control. There is exactly one Owner per workspace. The Owner can transfer ownership to another Admin. Owners cannot be removed from the workspace by anyone — only by transferring ownership first.
- Admin: Can manage most things including members, asset types, and schema configuration. Cannot delete the workspace or transfer ownership. Suitable for senior IT staff who need to configure the environment.
- Member: Standard access for day-to-day inventory work. Can create and edit assets and employees, manage assignments, and run reports. Cannot delete assets or change workspace configuration. Suitable for IT technicians and inventory managers.
- Viewer: Read-only access. Can browse the full inventory (subject to asset visibility rules) and export reports, but cannot create or modify anything. Suitable for stakeholders, auditors, or executives who need visibility without write access.
Permission Profiles
Permission profiles add a second layer of access control on top of roles. They are named sets of restrictions that can be applied to individual members. The key design principle is that profiles can only restrict what a role grants — they cannot expand permissions. A Member with a restrictive profile cannot gain Admin-level access; they can only lose some of the Member capabilities.
Example use cases:
- “Auditor” profile (base: Viewer): Standard viewer with no additional restrictions — used to formally label external auditors in the member list.
- “Inventory Staff” profile (base: Member): Restrict deletion (even though Member normally can’t delete, this profile could restrict editing of certain field types) and disable export to Notion.
- “Read-only Admin” profile (base: Admin): An Admin who can see everything and manage members, but cannot modify the asset schema or workspace settings — useful for a manager who oversees access without touching configuration.
Profiles and governance are administered in the Administration Hub (/workspace/administration) in the sidebar, organized into five sub-views:
- Overview: Workspace membership totals, role distributions, and cloud sync status (
/workspace/administration/overview). - Members: Member list, active role assignments, and permission profile allocation (
/workspace/administration/members). - Invitations: Issue and revoke team invitations by email (
/workspace/administration/invitations). - Permission Profiles: Create, configure, and inspect named permission profile overlays (
/workspace/administration/profiles). - Asset Visibility: Centralized catalog of restricted assets and their profile access grants (
/workspace/administration/visibility).
Asset Visibility Architecture
Beyond role-based access to the workspace, individual assets can have granular visibility restrictions enforced authoritatively via Supabase Row Level Security (RLS):
- Everyone (default): All workspace members who have access to the workspace can see this asset.
- Admins only: Only Owners and Admins can see and interact with this asset. Members and Viewers see no trace of it. Suitable for executive laptops or core security infrastructure.
- Restricted: Only members assigned to specific permission profiles granted access via
computtite_asset_visibility_grantscan see the asset.
All visibility filtering happens at the database layer. Unauthorized users receive no rows in SQL queries, so restricted assets do not appear in searches, asset counts, reports, or exports.
Real-Time Role Sync
Starting in v3.5.2, role and permission profile changes propagate to the affected member’s running session in real time — they do not need to restart the app or re-login. If an Owner or Admin changes your role, your session updates immediately to reflect the new capabilities. If your workspace membership is revoked entirely, the app redirects you to the workspace selector automatically.
This means permission changes take effect the moment they are saved, not on the next session. For sensitive role downgrade scenarios (e.g., revoking a member’s edit access while they are actively working), the change is enforced within seconds.
Workspace Tone and Governance Visibility
When the workspace tone is set to Simple, some governance controls are hidden behind secondary menus to reduce cognitive load for non-technical users. Switching to Advanced tone surfaces all governance controls, permission details, and visibility settings at the top level. This setting does not change any permissions — it only affects the UI’s presentation.