Directory journeys

Table of Contents

The roster is the administrator's starting point, and creating an account is the journey that fills it. Both treat an account as a record in a directory rather than as one person's own details.

The roster journey has no single entity behind it. Its usefulness comes from joining the account, its sign-in state, its parties and its roles into one row, so the administrator can see who is locked, who is online, and who must change their password at next sign-in. That join is the journey's real work.

An account is not always a person. It has four types — user, service, algorithm and llm — and only the first has a photo, a job title, a contact record or a party in the ordinary sense. A non-human account is still an identity that logs in, holds roles and appears in provenance, so it is created and managed here, but the journey is not the same one.

1. Journeys

Journey Actor Gist
See who has access tenant administrator Read the roster and each account's state
Bring someone in tenant administrator Create a person's account with its parties, roles and first password
Register a service account tenant administrator Create a non-human identity for a service, an algorithm or an LLM

2. Related

Emacs 29.3 (Org mode 9.6.15)