Authority is shown as aggregate cohorts, privacy-floor withholding and explicit access-model gaps.
Roles & access
Every authority this product actually has, what each one can do, how many people hold it — and, at the same weight, the roles the design asks for that do not exist yet.
Access to these workspaces is one authority, not five: it rests entirely on the Entra role, and everyone who holds it can change everything this shell can change. counted
The authorities that exist today
What the gate actually enforces, read out of the code rather than out of an intention.
Scroll sideways for the remaining columns.
| Authority | How it is granted | What it can and cannot do | Who holds it |
|---|---|---|---|
| Leader
not enumerable |
An application role assigned in Microsoft Entra — Leader or Sponsor — or membership of the Entra group this organisation has named as its leader group. Never a job title: a title anyone can type into their own profile is not an authority. | Can: Open every workspace in this shell, set the seat cost and the monthly budget, pause all outreach, generate and schedule reports, and move any finding through its lifecycle.
Cannot: Nothing this shell offers. The authority is not divided by module, which is the single largest gap in this model and is named below. |
—
Aristo cannot count them, and does not try. It never reads this organisation's Entra role assignments; it decodes the role claim in the token of whoever is signed in, at the moment they arrive. The list of who holds the role lives in Entra, where it is administered, and that is the only place it is authoritative. |
| Sponsor
configured list |
An address on the curated sponsor list in this organisation's own settings, matched against the signed-in account. | Can: Everything a Leader can. The gate admits the two identically — this is a second door to one authority, not a lesser tier of it.
Cannot: Nothing a Leader cannot. If that is not what was intended, the list is the control: this is the authority it confers. |
0
Nobody is on the list. Access rests entirely on the Entra role. |
| Microsoft account team
configured list |
A time-boxed grant issued by a leader of this organisation to a named, sign-in-verified Microsoft seller. Ninety days by default, revocable at any moment, and every issue and revocation is in the audit trail. | Can: Read the surfaces the grant covers. It writes nothing, ever.
Cannot: Change any setting, generate any report, move any finding, or see anything after the grant expires or is revoked. |
0
Nobody outside this organisation holds a grant right now. |
| Platform operator
not enumerable |
A session belonging to the vendor's own tenant. It is not granted by this organisation and cannot be granted or revoked from any customer surface. | Can: Everything a Leader can, and a plane no customer role reaches: registering organisations, the module switchboard, the AI vendor pin, the named-recognition posture, revoking every outstanding shared link, and the platform-wide rollback.
Cannot: Act without leaving a line in the audit trail. Every operator act writes one, under the operator role, and the trail is on the history page beside this one. |
—
Held by the vendor rather than by this organisation, so its size is not a fact this product can report to you. It is named here because a role model that omits the vendor's own access has told you the least interesting half of the truth. What it does is auditable, and the audit is not the vendor's to edit. |
| Holder of a shared link
not a population |
Possession of a sealed link that a leader generated and sent. | Can: Read the specific surface the link was minted for.
Cannot: Write anything, or reach any other organisation. Every outstanding link for this organisation can be invalidated at once by revoking the seal, which is an operator act and appears in the trail. |
—
Not countable, and counting it would be the wrong idea: a link is a capability rather than an identity, and Aristo does not know who is holding one. That is the honest cost of a shareable link, and it is why the revocation is a single act that invalidates all of them at once. |
| Maker
measured population |
Building an agent. It is an ATTRIBUTION, not an authority — it appears beside what somebody made and confers no access to anything. | Can: Nothing that anyone else cannot. It is listed here precisely because it looks like a role and is not one.
Cannot: Open a workspace, read a figure or change a setting on the strength of having built something. |
<5
Fewer than 5 people have built one, so the number is withheld — but the fact that agents were built is not. A count of PEOPLE below the disclosure floor can identify them in a small team, and this product will not print one at any size below it. |
| Everyone else
not enumerable |
A signed-in work account with none of the above. | Can: See their own hours-returned page, and ask for access — which notifies this organisation's own leaders rather than the vendor.
Cannot: Open any surface carrying organisation-wide money. The refusal is a page explaining what the surface holds and who may open it, never a blank error. |
—
Everyone in the organisation who is not on one of the lists above. Aristo holds no roster of its people and does not build one to answer this question. |
The five roles the design asks for
Rendered at the same weight as the table above, because a buyer needs the gap more than the promise.
Scroll sideways for the remaining columns.
| Role | What it focuses on | State | The honest answer |
|---|---|---|---|
| Executive | outcomes, risk, money, trend, recommendations | Served | Served by the Leader authority, and by the Executive Summary and Home workspaces which are built for exactly this reading. |
| Finance | allocation, budget, chargeback, variance, exports | Partly served | The WORKSPACES exist — the whole License Chargeback module is this reading — but there is no Finance ROLE. A finance colleague is admitted as a Leader or a Sponsor, which means the person you wanted to give a budget view to can also change the budget. That is a real gap and it is the one most likely to matter first. |
| IT | licenses, adoption, workloads, policies, integrations | Partly served | Same shape. Adoption, Users & teams, Security and Integrations are all built for this reading, and there is no IT role that grants them without also granting everything else. |
| Department leader | team spend, usage, recommendations, comparison | Not served | Not served, and this is the largest gap in the model. There is no way to admit somebody to their OWN department only. Every surface in this shell composes the whole organisation, so a department-scoped authority would need a department-scoped composition that does not exist — and issuing one against the existing composition would hand a department head the whole estate. It is refused rather than approximated. |
| Admin | setup, integration health, permissions, data quality, audit | Partly served | Setup, integration health, permissions and audit all have surfaces, and a Leader reaches every one of them. But the administrative plane that would make this a distinct role — provisioning, the module switchboard, the posture settings — is held by the platform operator rather than by this organisation. |
Access model boundaries
Explicit by design, so a security reviewer can see exactly what each role can and cannot do.
Every authority that may open a workspace may also change what that workspace reports on. There is no read-only leader. A buyer who wants an auditor, a board member or a finance analyst to SEE the numbers without being able to move them cannot have that today, and no combination of the existing roles produces it.
Authority is granted to the whole shell at once. The composition every page reads is organisation-wide by construction, so a scoped grant is not a permission check that was skipped — it is a composition that has not been built.
A budget, a seat cost and a pause all take effect the moment they are confirmed. There is no second pair of eyes and no pending state. What exists instead is the record: every one of those acts is in the audit trail before the page has finished redirecting.
The only expiring authority in this product is the one issued to an outside Microsoft seller. An internal grant lasts until somebody removes the address or Entra removes the role. There is no "for the next two weeks" for a colleague.
Which is a deliberate choice rather than an omission, and it is worth stating as one. Leadership comes from Entra, where this organisation already administers identity and already has its own approval and review processes. A product that let you mint an authority inside itself would be a second identity system to audit.
Every grant on this page is scoped to one organisation and cannot see another. There is no cross-organisation reader to switch between, and no link — a report, an insight, a saved view — can be followed out of this tenant into a different one. The single exception is the outside Microsoft seller grant above, which expires, and which reads the summary it is granted rather than the workspaces.
How this page behaves
The decisions behind what it does and does not show.
No filter and no export. This is a short, fixed list of authorities rather than a collection, and the thing a reader would want to export — the record of what these roles have actually done — is the history page, which owns it.
No address, under any rule. Not a sponsor's, not a seller's, not a maker's. Counts and states only. A leader who needs to change a list is one link from the screen that legitimately shows it; everyone else gets the number.
Reaching this page requires the same authority as every other workspace, which is itself an illustration of the gap named above: there is no lesser authority that could be given a look at the role model without also being given the organisation's money.