Who works for Toko and what they may do. A separate surface outside the studio — not project admin. Four roles, one capability matrix, and one hard ceiling: platform authority grants read-only visibility into projects and no write path into any of them.
Toko has three permission systems and none grants another: platform authority (here), studio access (the beta gate), and project roles (what a member does inside a project).
01Staff list · the home surfaceEvery account holding a platform role. One role per account — never stackable. Keyed by stable Toko User ID, so a rotated principal never loses or duplicates authority.
Showing 5 of 7 staffOne role per account · keyed by User ID
02Grant authority · only a Super Admin sees thisGranting, changing or revoking platform authority is Super Admin only. An Admin may revoke a creator's studio access but cannot promote, demote or remove staff — two distinct powers, deliberately at different tiers. Identity is looked up, never authored: the account's own profile name and User ID render read-only.
Look up the account, choose a role, and record why.
Account
Principal is accepted as a lookup route; the grant is keyed by User ID.
Jon Park
usr_01HM2P9XR4TC · e9f0…3abc
What Support can do
Look up accounts & admin recordsYes
Edit internal notesYes
View any projectRead-only
Manage studio accessNo
Moderate contentNo
Kill switchesNo
Change anything in a projectNo
i
This grant does not give Jon studio access, and does not add him to any project. Those are separate.
03The capability matrixNine capabilities, four roles. The front end derives every platform check from one mapper that mirrors this — never a second mapper. Two rows are empty across all four roles on purpose, so nobody reads their absence as an oversight.
Canonical matrix · platform-authority-design.md
Capability
Super Admin
Admin
Moderator
Support
Manage platform authority
✓ only
—
—
—
Manage studio access — grant / revoke / restore
✓
✓
—
—
Moderate content · takedown · review outcomes
✓
✓
✓
—
Manage kill switches & feature flags
✓
✓
—
—
Manage vault registry
✓
✓
—
—
Manage the RWA allowlist
✓
✓
—
—
Bypass the studio gate
✓
✓
—
—
View any project — read-only
✓
✓
✓
✓
Look up an account & view its admin record
✓
✓
✓
✓
Edit internal notes
✓
✓
✓
✓
Change anything inside a project
—
—
—
—
Withdraw from a project treasury
—
—
—
—
The two red rows are empty deliberately. No platform role may change a project, and none may withdraw from a project treasury — withdrawal stays Treasurer-exclusive, where not even the project's own Creator has it. Staff who must act inside a project are added to it as ordinary members. Moderator has no kill switches — a takedown removes one thing, a kill switch stops a surface. Support can edit notes: they are not a change of access, they are audited, and they are how support records context.
04Read-only is the ceiling on project accessStaff can see any project in full and change nothing in it. Staff presence is visible and attributed — they appear in the project's access view as Toko staff, and every action and view is logged with actor and timestamp. That is what makes the transparency promise real rather than aspirational.
Read-only. You are viewing this project as Toko staff. To change anything here you must be added to the project by its Creator, and you would then act under your project role — not this one.
Project
CreatorMara Okafor
Collections4 · 2 Live
Studio accessActive
Cycles runway~34 days
Visible to the project
i
The project's own access view lists you as Toko staff · read-only, and this visit appears in its activity log.
TreasuryNot available
Edit collectionsNot available
Manage membersNot available
05Revoke authority · and the two guards that stop a lockoutCanonical red destructive confirm, left-aligned, no character illustration. Two invariants protect the surface: at least one Super Admin exists at all times — the last one cannot be demoted or revoked — and no self-disarm, so a Super Admin cannot revoke their own authority-management capability.
Revoke platform authority · Ana Silva?
✕
Ana Silva immediately loses Moderator authority — no moderation queue, no takedowns, no content review. Her Toko account is untouched, and any studio access or project roles she holds are unaffected. This can't be undone, but you can grant authority again at any time.
Can't revoke · last Super Admin
✕
✕
Mara Okafor is the only Super Admin. Revoking her would leave nobody able to manage platform authority. Grant Super Admin to another account first, then try again.
Super Admins1
Minimum required1
06Audit log · append-only, including viewsEvery platform action is recorded, and changes to platform authority are recorded too. StaffProjectViewed is what makes read-only access accountable — access is still access, and a creator can see that Toko looked.
Append-only. Actor, target, timestamp, and the role before and after where it applies.
PlatformRoleGrantedJon Park → Support · by Gabriel Reyes · "Joined support team, Aug intake"11 Aug 2026 · 09:14
StaffProjectViewedNeon District · by Ana Silva18 Aug 2026 · 16:02
PlatformRoleChangedGabriel Reyes · Moderator → Admin · by Mara Okafor03 Mar 2026 · 11:40
NotesEditedSolara Works record · by Jon Park18 Aug 2026 · 14:22
PlatformRoleRevokedTomas Berg · Admin → none · by Remco Vos · "Left the company"02 Aug 2026 · 17:55
07Toko admin area navigationA destination list, not a drawn sidebar. The admin area is its own surface, reached outside the studio. Only the first two destinations exist today — the rest arrive with the flows that own them.
Admin area destinations · what exists and what is owed
1Platform staffthis spec
2Studio accessspecified
3Projects — read-onlythis spec
4Moderation queueundesigned
5Kill switches & flagsundesigned
6Vault registryPhase 5
7RWA allowlistPhase 5
8Audit logthis spec
What this spec does and does not settle
It assigns the authority for every destination above. The flows for moderation, kill switches and observability are undesigned in beta-readiness-failsafes.md §3.1–§3.3. When they are designed they consume these capabilities rather than inventing their own roles.
Takedown is the one open boundary. Platform authority is otherwise read-only on projects, but a moderation takedown must be able to withdraw published work. That spec owes the rule for what a takedown may touch and whether a creator can appeal.
Out of scope entirely: canister and fleet operations. Those belong to the separate fleet-management system, and platform authority never implies infrastructure authority.