Roles, access, and assistant
Review the target role matrix, read and mutation boundaries, cross-product access, and the answers each role may receive.
Approved access catalog · shadow rollout active
Roles, access, and assistant boundaries
This catalog is implemented in Trailhead's canonical shadow model and visible in Company Settings. Shadow assignments are audit evidence while legacy authorization still controls effective access, so they are not proof that every current account already matches the target. Review actual assignments before canonical cutover and after every role change.
Access is the result of five gates
A job title by itself is never enough. Native pages, APIs, reports, and the assistant must all pass the same five checks.
- 1Identity — the signed-in person and active company are known.
- 2Product access — Trailhead or SettleWise entry is explicitly enabled.
- 3Role — a stable job profile supplies a bounded set of permissions.
- 4Action permission — the exact read, change, or approval is allowed.
- 5Scope — the company, workspace, lodge, assignment, or self boundary still applies.
One question must produce role-appropriate answers
For the question “How are we doing this season?”, the assistant changes the lens—not only the wording.
| Role | Permitted answer | Must leave out |
|---|---|---|
| Trailhead Executive | Commercial and operating performance, Analytics, risks, and decisions that need executive attention, with confirmed facts and forecasts kept separate. | SettleWise Accounting, Inventory, Treasury, and Chart of Accounts unless separately assigned. |
| Trailhead Sales | Confirmed revenue-bearing and FOC bednights, classification completeness, commercial target progress, conversion, pipeline as forecast, and client-readiness blockers. | Analytics, Settings, costs, cash, margin, internal strategy, operations-only detail, Guide schedules/private data, and Chart of Accounts. |
| Operations | Operating demand, readiness, CIS, Programs, Fishing Guide, Assistant and POA assignments, reports, and blockers needed to run the season. | Analytics, Settings, people/role administration, and Program-conflict resolution. |
| Head Guide | Fishing-delivery readiness, Guide capacity, Fishing Guide, Assistant and POA assignments, field risks, reports, and Program conflicts escalated for a final decision. | Analytics, Settings, people/role administration, and SettleWise workspaces. |
| Lodge Manager | Only the current daily and weekly operating context: CIS read-only, today's Guests, weekly meals, relevant notifications, and preference notes. | Company season totals, CIS editing, assignments, Programs, Accesses, Knowledge, Analytics, Settings, finance, and other Guest profile fields. |
| Fishing Guide, POA Guide, or Assistant | Own assignments, safe trip context, personal readiness, and permitted field references. | Lodge or company season totals, targets, other people's information, finance, and strategy. |
Trailhead company-role matrix
A person has at most one Trailhead company role. A field role may be added only when the person genuinely performs both jobs. Guide Coordinator is a daily lodge duty selected from explicit guide ranking, not another company role. Trailhead does not need workspaces today.
| Role | Primary lens | May see | May change or decide | Explicit boundary |
|---|---|---|---|---|
| Trailhead Executive | Business and security authority | All Trailhead business and operational information, including Analytics, Settings, people, roles, and management reporting. | Manage Settings, people and roles, Accesses, and high-impact business decisions. | Field assignments and Program-conflict resolution are reserved for the named operational roles; SettleWise workspaces unless assigned independently. |
| Trailhead Sales | Commercial work | Commercial workflow, client readiness, Light CIS, commercial reporting, and minimum Guide availability for requested dates. | Maintain the commercial pipeline and create Light CIS records. | Analytics, Settings, finance, Guide schedules/private data, assignments, operations mutation, people/roles, and Chart of Accounts. |
| Operations | Operations | CIS, Programs, Guests, Fishing Guide, Assistant and POA assignments, weekly meals, Accesses, Knowledge, Gear, reports, and operational blockers. | Run ordinary operations and assign Fishing Guides, Assistants, and POA Guides. | Analytics, Settings, people/roles, Program-conflict resolution, and SettleWise workspaces. |
| Head Guide | Fishing delivery leadership | All approved Trailhead operational information needed to lead fishing delivery, including roster, readiness, alerts, and Program conflicts. | Assign Fishing Guides, Assistants and POA Guides, make the final decision on escalated Program conflicts, maintain Guide readiness, and resolve operational red flags. A Head Guide may separately hold the daily Guide Coordinator duty. | Analytics, Settings, people/roles, and SettleWise workspaces. |
| Lodge Manager | Daily guest service | CIS read-only, today's Guests, weekly meals, and relevant notifications. | Edit Guest preference notes only. | CIS editing, assignments, Programs, Accesses, Knowledge, Analytics, Settings, people/roles, finance, and all other Guest profile fields. |
Field-role matrix
Fishing Guide, POA Guide, and Assistant access remains limited to the person and their own assignments. The daily Guide Coordinator receives only the conflict capabilities for the assigned lodge and operational day. One current lodge does not justify broad company access.
| Role | Primary lens | May see | May change or decide | Explicit boundary |
|---|---|---|---|---|
| Fishing Guide | Own field work | Own assignments, safe trip context, signals, and self profile/account. | Submit own field updates, Fishing Reports, alerts, and seasonal-kit request. | Other people, other assignments, lodge portfolios, roster, finance, and approvals. |
| Guide Coordinator · daily duty | Lodge conflict coordination | Shared Program conflicts, affected Programs, and safe alternatives for the assigned lodge and operational day. | Resolve routine Program conflicts in mobile or escalate the complete conflict to Head Guide. The duty starts with the lodge-local day, follows explicit guide ranking, and accrues USD 30 once per guide and date. | This is not a permanent company role and grants no authority over another lodge or day, Guide roster, people, Settings, finance, or Head Guide final escalation unless the person independently holds that role. |
| POA Guide | Own POA work | Own POA assignments, permitted POA context, weekly meals, and self profile. | Maintain own POA Program activity and request own seasonal kit. | Fishing Reports or any other report submission, Fishing Guide/Assistant work, assignments, company totals, finance, and approvals. |
| Assistant | Own supporting work | Own assignments, safe field references, weekly meals, and self profile. | Request own seasonal kit only. | Reports, Programs, operational mutation, other people or assignments, company totals, roster, finance, and approvals. |
Mutation and approval rules
Read access does not imply write access, and ordinary work does not imply approval authority.
| Action | Who may do it | Required boundary |
|---|---|---|
| Invite members or change standard Trailhead access | Trailhead Executive | Same company only; no self-promotion; every change is audited. Martin and Benja are the intended Executive holders, but authorization is role-based. |
| Create or edit Guide roster and eligibility records | Head Guide | Roster mutation remains separate from assignment coordination. |
| Assign or reassign a Fishing Guide on a CIS | Operations or Head Guide | Eligible Fishing Guides only. The CIS and Guide must be in scope, and the server rechecks availability at confirmation. |
| Assign or reassign an Assistant on a CIS | Operations or Head Guide | Eligible Assistants only. This capability never grants Fishing Guide or POA assignment. |
| Assign or reassign a POA Guide | Operations or Head Guide | Eligible POA Guides only. This capability never grants Fishing Guide or Assistant assignment. |
| Resolve a Program conflict | Daily Guide Coordinator; Head Guide after escalation | Guide Coordinator is selected per lodge and local day from the top-ranked active guide working there. The server rechecks current duty ownership, conflict revision, alternatives, and impact before confirmation; Head Guide is the final authority only after escalation. |
| Edit a Guest preference note | Lodge Manager, Operations, Head Guide, or Trailhead Executive | Preference-note field only. No identity, profile, commercial, or financial field may change. |
| Create or update ordinary operating records | Operations, Head Guide, or Trailhead Executive; Fishing Guide or POA Guide only for explicitly permitted own work | The exact permission and resource scope must be checked for every change. |
| Maintain commercial pipeline or create Light CIS | Trailhead Sales or Trailhead Executive | Commercial scope only; handing a confirmed trip to Operations does not grant operational mutation. |
| Review or confirm weekly meals | Operations, Head Guide, or Trailhead Executive | Lodge Manager, POA Guide, and Assistant may read the safe weekly view but cannot review or confirm it. |
| Read, post, approve, or configure SettleWise Accounting | The matching SettleWise Accounting workspace role | A Trailhead role never supplies this authority. Operator and Approver remain separate unless an audited exception is approved. |
| Prepare or confirm an action through the assistant | Only a person already authorized for the same native action | The assistant rechecks role, scope, target, and confirmation at execution time. A prompt never grants authority. |
Assistant enforcement rules
The assistant has no special AI role. It projects the person's current access and must become narrower whenever the person's scope is narrower.
- 1. Resolve the signed-in person's current product, role, action permission, and scope before reading data or mounting a tool.
- 2. Use the role's permitted lens. Do not create one generic management answer and merely hide a few fields.
- 3. Never reveal that an inaccessible record, lodge, person, metric, or account exists.
- 4. Keep confirmed actuals, active holds, pipeline forecasts, targets, and financial bases explicitly separate.
- 5. A read may summarize or deep-link. A mutation requires the native action permission, an in-scope target, explicit confirmation, and an audit event.
- 6. After any role or scope change, discard prior pending confirmations and calculate access again.
Client review checklist
- Name one accountable owner for each role and every high-impact approval.
- List each person's Trailhead company role, field role, and separate SettleWise workspaces.
- Test at least one permitted read, one refused read, one permitted mutation, and one refused mutation per role.
- Repeat the same checks through the assistant; a prompt must never widen access.
- Revoke old invitations, legacy flags, and stale assignments after the new role is active.
Conversations that help complete a task
The assistant should answer your question, retain context across turns, and propose a useful next step when the available evidence supports one. You can accept that proposal, decline it, or correct the scope. A complete answer does not always need another question.
We evaluate four things separately: factual accuracy, continuity, corrections, and useful initiative. The assistant should use evidence, remember the task, apply your correction to its next answer, and explain why a proposed step helps. You can decline a proposal without being pushed toward it again. Generic offers and unnecessary questions do not demonstrate useful initiative.
These checks contribute to the Trailhead App Readiness Model for the relevant task, role, and surface. A good conversation alone does not establish that the whole app is ready. Missing evidence and failed checks stay visible separately.
For example, start with “What information is missing for this Access?”, continue with “Only completed usage in November”, and then ask about agreement costs if your role permits it. The assistant should preserve the Access and period, distinguish planned from completed activity, and explain missing evidence. Access usage and Beat pressure are different questions. Accesses and Guides do not require a lodge to establish their ownership.
In the Playbook, use each journey's Story → Flow → Reproduce path: start with the job, continue through a correction and a proposed next step, and check the expected result. Pagination changes the visible page directly; it should not send a chat prompt. Focused follow-ups should not repeat the full list.
Assistant improvement work currently starts with Accesses, including usage and finance, then Beats, CIS, Guides, and Programs. This is a validation sequence, not a claim that all conversations are available or verified. Authored evaluation cases and verified live conversations represent different levels of evidence; use the journey's coverage information when available.