---
title: "Platform Roles and Security Scopes"
description: "Sources: `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema`, `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema`."
engineVersion: v1.0.234
date: 2026-09-28
license: "(c) Gessa, proprietary. Cite with attribution to https://gessa.ai/docs/. Terms: https://gessa.ai/terms/."
canonical: https://gessa.ai/docs/spec/generated/roles/
---
<!-- GENERATED FILE: do not edit by hand. -->
<!-- Regenerate with `npm run gen-docs`. -->

Sources: `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema`, `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema`.

# Platform Roles and Security Scopes

This generated snapshot is derived from `PlatformRoleSchema` and `SecurityScopeSchema` in `packages/protocol/src/platformAuthCore.ts`. Platform roles are the closed set of identity roles a principal may hold; security scope types are the closed set of targets a role assignment or capability grant can name.

Both are bare Zod enumerations and carry no per-entry description field in their schema, so no description text is projected for individual roles or scope types.

Workspace collaboration roles and permissions are defined as TypeScript types and module-private constants in `server/src/modules/workspace-collaboration/rbac.ts`; they are not runtime-enumerable through an exported registry and are not projected here.

Platform role count: `15`.
Security scope type count: `12`.

## Platform roles

The closed set of platform identity roles, enumerated by `PlatformRoleSchema`.

`PlatformOwner`, `PlatformSupport`, `OrgOwner`, `WorkspaceOwner`, `GameOwner`, `Developer`, `Designer`, `LiveOps`, `Support`, `Analyst`, `BillingAdmin`, `Player`, `ServiceAccount`, `AIWorker`, `ExternalIntegration`

### PlatformOwner

| Field | Value |
| --- | --- |
| Identifier | `PlatformOwner` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### PlatformSupport

| Field | Value |
| --- | --- |
| Identifier | `PlatformSupport` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### OrgOwner

| Field | Value |
| --- | --- |
| Identifier | `OrgOwner` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### WorkspaceOwner

| Field | Value |
| --- | --- |
| Identifier | `WorkspaceOwner` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### GameOwner

| Field | Value |
| --- | --- |
| Identifier | `GameOwner` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### Developer

| Field | Value |
| --- | --- |
| Identifier | `Developer` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### Designer

| Field | Value |
| --- | --- |
| Identifier | `Designer` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### LiveOps

| Field | Value |
| --- | --- |
| Identifier | `LiveOps` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### Support

| Field | Value |
| --- | --- |
| Identifier | `Support` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### Analyst

| Field | Value |
| --- | --- |
| Identifier | `Analyst` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### BillingAdmin

| Field | Value |
| --- | --- |
| Identifier | `BillingAdmin` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### Player

| Field | Value |
| --- | --- |
| Identifier | `Player` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### ServiceAccount

| Field | Value |
| --- | --- |
| Identifier | `ServiceAccount` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### AIWorker

| Field | Value |
| --- | --- |
| Identifier | `AIWorker` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |
### ExternalIntegration

| Field | Value |
| --- | --- |
| Identifier | `ExternalIntegration` |
| Kind | platform role |
| Source | `packages/protocol/src/platformAuthCore.ts:PlatformRoleSchema` |

## Security scope types

The closed set of scope targets, enumerated by the `type` field of `SecurityScopeSchema`.

`platform`, `organization`, `workspace`, `game`, `environment`, `deployment`, `world`, `player`, `asset_folder`, `data_store`, `mcp`, `agentenv`

### platform

| Field | Value |
| --- | --- |
| Identifier | `platform` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### organization

| Field | Value |
| --- | --- |
| Identifier | `organization` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### workspace

| Field | Value |
| --- | --- |
| Identifier | `workspace` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### game

| Field | Value |
| --- | --- |
| Identifier | `game` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### environment

| Field | Value |
| --- | --- |
| Identifier | `environment` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### deployment

| Field | Value |
| --- | --- |
| Identifier | `deployment` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### world

| Field | Value |
| --- | --- |
| Identifier | `world` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### player

| Field | Value |
| --- | --- |
| Identifier | `player` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### asset_folder

| Field | Value |
| --- | --- |
| Identifier | `asset_folder` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### data_store

| Field | Value |
| --- | --- |
| Identifier | `data_store` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### mcp

| Field | Value |
| --- | --- |
| Identifier | `mcp` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
### agentenv

| Field | Value |
| --- | --- |
| Identifier | `agentenv` |
| Kind | security scope type |
| Source | `packages/protocol/src/platformAuthCore.ts:SecurityScopeSchema` |
