Shared standards without a shared blast radius.
Give every team a governed workspace while keeping organization-wide operations visible and configurable.
Four roles with a clear floor
Viewer is read-only. User can preview and copy without deleting production or restoring. Manager adds destructive jobs and member/worker management. Owner controls bucket destinations, roles, ownership transfer, and deletion.
Adjust the matrix centrally
Site administrators can edit the DB-backed role-to-permission matrix. Updates invalidate the application cache immediately, while user-to-role lookups remain live so revocation takes effect without a TTL delay.
One owner, transferable
Every team has exactly one owner, enforced at the storage layer. Ownership transfer is atomic; the previous owner becomes a manager rather than losing access entirely.
Your buckets. Your workers. Your control.