Can authorize founder-level actions after explicit confirmation and elevated verification.
Founder role must still pass consent, MFA, and audit boundaries.Verified identity is not authority. Role is the boundary.
A role classification readiness layer that defines founder, operator, reviewer, system, and observer authority before identity can be used for real persistence or control.
Every TheoB pathway can move through Past, Present, and Future without losing context.
Read current signals, conditions, and live context.
Voice ready
No role, no authority.
Actor Role Classification Readiness Layer defines who can view, review, operate, recommend, or authorize. Founder authority, operator delegation, reviewer separation, system limits, and observer read-only boundaries must be clear before identity becomes usable.
Actor role classification is intentionally not ready until founder authority, operator delegation, least privilege, role-change auditing, and critical-action authority rules are finalized.
Can operate assigned cockpit workflows within delegated scope.
Operator authority must be explicitly delegated and revocable.Can inspect records, flag issues, and verify governance requirements.
Reviewer can advise, not command.Can generate structural status, readiness reports, receipts, and non-destructive simulations.
System role must never silently escalate into human authority.Can view public-safe or permissioned summaries without control authority.
Observer role is read-only by default.Every authenticated actor must be assigned an explicit role.
No authenticated actor should float around as undefined authority.Founder authority must be explicitly granted, never inferred from login alone.
No accidental founder power from generic auth.Operators must have a defined scope, expiration, and revocation path.
Operators can help steer the ship, not claim the throne.Reviewer authority must remain separate from execution authority.
Review and command should not collapse into one button.System-generated recommendations must never become self-approved actions.
No machine should crown itself founder.Observers can see safe summaries but cannot confirm or mutate actions.
Viewing is not authority.Persistence activation, safe mode activation, and autonomy pause require founder-level authority.
Critical controls stay behind founder confirmation.Future role assignment, delegation, promotion, or revocation must produce an audit record.
No invisible permission changes.New actors should start with observer or no-control authority until elevated.
Default small. Expand carefully.Role records should expose safe labels and avoid sensitive auth payloads.
Role metadata should not leak raw identity data.