Skip to content

Operators and access

Operators are the people who sign in to the Churchill console. This page explains the two roles an account can hold, how CAB membership fits in, where to see who has access, and how the owner manages accounts and lockouts.

Every account is an operator. A signed-in operator has the full run of the console: fleet, host detail, evidence, recordings, and the governance workflow. There are no per-page permissions.

Some accounts are additionally the owner. The owner carries the tenant through initial setup: they run the CAB ceremony on first sign-in, manage CAB membership, and can view and export the sealed setup receipt from Settings. The owner is also the only one who can invite and manage operator accounts. Everything else works the same for owners and operators. See CAB overview.

CAB membership is a separate axis from both roles. A CAB member holds a signing passkey and approves changes. That passkey also signs the member in to the console, so a CAB member can operate the dashboard, but their board seat and their console access remain separate grants. If your account is linked to a CAB key, it appears on your Profile.

Open Settings and select the operators tab. Any signed-in operator can view the roster, and the header shows a count of accounts. See Settings.

Column Meaning
Who The account’s display name, with its identity (for example you@westgate) beneath. Your own row is marked “(you)”.
Role owner or operator.
State active or disabled, shown as a colored pill. Only active accounts can sign in. Owners also see a locked pill on identities locked by failed sign-ins.
Passkeys How many passkeys are registered to the account.
Last active When the account last signed in to the console. Shown as a dash for an account that has never signed in.

If the console cannot load the roster, the card shows Operator roster unavailable with a short reason. Refresh once the underlying store recovers.

The owner creates accounts by email invitation. On the operators tab, the Pending invitations card carries the Invite operator… button. The owner enters a work email and a display name, then selects Send invitation. The email goes out immediately.

The invited person confirms their identity from the emailed link and creates a passkey. That passkey is the account’s only sign-in credential. No password is ever set. The invitation grants console access only, not a seat on the CAB. Invitation links are valid for seven days, and the token rides the link itself, so each link is personal and single-use.

The Pending invitations card tracks outstanding invites with sent or expired state pills, the send and expiry times, and per-row Resend and Revoke buttons. Redeemed and revoked invitations drop off the list. When nothing is outstanding, the card reads “No invitations are outstanding.”

The owner manages accounts per row on the roster:

  • Rename changes the display name shown across the dashboard. The sign-in identity and existing audit-chain entries are unchanged.
  • Disable signs out every session the operator holds, immediately, and refuses all further sign-ins. Their passkeys and password are kept, so Enable restores access without re-enrolling anything.
  • Unlock appears on a locked identity and clears the lockout.

If a disabled operator holds a CAB seat, the dialog warns you: “Their signing key and board membership are untouched — only console access stops”. They still count toward a quorum they cannot sign in to reach. Remove the seat from the CAB page if that is the intent. Disabling is still allowed.

Two limits apply. The owner’s own account cannot be disabled, though it can be renamed and unlocked. And there is no console control to change an account’s role, reset a password, or delete an account.

Three failed password attempts lock an identity. A locked account cannot sign in at all, not with a password and not with a passkey. See Signing in.

There is no self-service reset. The owner clears the lock with the Unlock button on the roster. A signed-in owner can unlock their own row too. An owner who is locked out with no live session needs out-of-band recovery.