# verae-staff-iam Named **internal staff** accounts with **roles and permissions**. Source of truth for who may use CS, sales, accounting, the staff plane, the operator console, and the billing admin console. **Forgejo:** https://git.georgelambert.org/marchon/verae-staff-iam Port **`:3028`**. UI: sign-in, people, roles, audit. ## Seed lab users | Username | Password | Roles | |----------|----------|--------| | `admin` | `admin-dev-key` | owner (all) | | `cs` | `cs-dev-key` | cs | | `sales` | `sales-dev-key` | sales | | `accounting` | `acct-dev-key` | accounting | | `operator` | `fleet-dev-key` | operator | Override with `IAM_OWNER_PASSWORD`, `IAM_CS_PASSWORD`, etc. Persist: `STAFF_IAM_PATH`. ## Wire other doors ```bash STAFF_IAM_URL=http://127.0.0.1:3028 STAFF_AUTH=1 # department HTML still redirects if check fails ``` `GET /check?permission=cs.credit` — cookie or `Authorization: Bearer`. Cookie name remains `staff_session`. Multi-host: `STAFF_COOKIE_DOMAIN`. ## Roles `owner`, `iam-admin`, `billing-admin`, `cs`, `sales`, `accounting`, `operator`, `viewer`. Permissions are listed on `/roles`.