M19: teams (sharing, roles, team daemons, invites) #31

Open
opened 2026-10-02 01:51:18 +00:00 by jhgaylor · 0 comments
Owner

Depends on: #30, #12, #13
Blocks: #32, #34

From PLAN.md, "Control track → M19: teams (sharing, roles, team daemons, invites)".


Builds on M12 (principals and roles on each daemon) and M13 (presence, driving, attribution). Control becomes where principals come from; daemons still enforce.

  • Teams:
    • create a team, invite by email or link, and set roles (owner, editor, viewer);
    • membership changes are signed by an owner's device, and daemons verify them (the trust rule);
    • an owner can transfer ownership.
  • Team daemons:
    • illogicald join --team acme enrolls a machine that belongs to the team;
    • who may drive it is a team policy, with M14's trust grants for anything but VMs.
  • Sharing a session (M13's dialog):
    • pick a person or the whole team, set a role, choose "with history" or "from now";
    • the daemon wraps the session key for each member device (S15).
    • Revoking removes the grant, rotates the key, and cuts the person off within a second.
  • Presence (avatars, focus outlines, follow) flows through control as metadata, so people on different networks see each other.
  • Read-only links (replacing M4c's share tokens and M15's links):
    • a link with the key in its fragment shows one session live, read-only, with no account, until it expires;
    • "from now" by default;
    • control sees that the link was opened, never what it showed.
  • Guests (people outside the team) work as M14 says: their panes default to a VM (M20 when the team has hosted compute; otherwise a member's wisp).
  • Kill switch: an owner's illogical team lock revokes all links and invites and disconnects non-owners.
  • Done when:
    • two people at different companies, neither on a tailnet, join a team by invite;
    • each sees the other's session live, with avatars and focus;
    • control passes back and forth between them;
    • one runs a build on a team-owned box;
    • a read-only link works in a logged-out browser and dies at expiry;
    • removing a member cuts them off within a second.
**Depends on:** #30, #12, #13 **Blocks:** #32, #34 _From PLAN.md, "Control track → M19: teams (sharing, roles, team daemons, invites)"._ --- Builds on M12 (principals and roles on each daemon) and M13 (presence, driving, attribution). Control becomes where principals come from; daemons still enforce. - **Teams:** - create a team, invite by email or link, and set roles (owner, editor, viewer); - membership changes are signed by an owner's device, and daemons verify them (the trust rule); - an owner can transfer ownership. - **Team daemons:** - `illogicald join --team acme` enrolls a machine that belongs to the team; - who may drive it is a team policy, with M14's trust grants for anything but VMs. - **Sharing a session (M13's dialog):** - pick a person or the whole team, set a role, choose "with history" or "from now"; - the daemon wraps the session key for each member device (S15). - **Revoking** removes the grant, rotates the key, and cuts the person off within a second. - **Presence** (avatars, focus outlines, follow) flows through control as metadata, so people on different networks see each other. - **Read-only links** (replacing M4c's share tokens and M15's links): - a link with the key in its fragment shows one session live, read-only, with no account, until it expires; - "from now" by default; - control sees that the link was opened, never what it showed. - **Guests** (people outside the team) work as M14 says: their panes default to a VM (M20 when the team has hosted compute; otherwise a member's wisp). - **Kill switch:** an owner's `illogical team lock` revokes all links and invites and disconnects non-owners. - **Done when:** - two people at different companies, neither on a tailnet, join a team by invite; - each sees the other's session live, with avatars and focus; - control passes back and forth between them; - one runs a build on a team-owned box; - a read-only link works in a logged-out browser and dies at expiry; - removing a member cuts them off within a second.
Sign in to join this conversation.
No description provided.