Codex 0 · Chapter 04 — People
Chapter 04 of the institutional specification.
- Authority rank
- 2
- Version
- v2.0
- Adopted
- unrecorded
- Held by
- Stewardship Office
- System
- SYS-01
Source · docs/codices/CODEX-0/04-people.md · registered by rule
Specifies every user type the institution serves or employs, the lifecycle of a person across decades, and for each type what they see, what they own, and what they must never see.
04.0 Purpose
To fix the human side of the architecture before any surface is designed. Chapters 08, 11, 12, and 13 all derive their access decisions from the types specified here.
04.1 Scope and non-scope
In scope. The canonical Person, the two standing rules, the lifecycle model, all user types with their visibility contract, consent and data rights, and the accessibility obligation owed to every type.
Not in scope. Role storage and enforcement mechanics (Chapter 08), entity fields (Chapter 07), surface design (Chapter 11), agent behaviour (Chapter 13).
04.2 The canonical Person
04.2.1 One record
A human being known to the institution has exactly one Person record (ENT-01), for life. Identities (ENT-02) authenticate into it; memberships (ENT-03/ENT-04) and roles (ENT-05) attach to it.
04.2.2 The two standing rules
- 1A person is never duplicated to give them a new relationship. A scholar who becomes a mentor, then an advisor, then an investor is one Person with four scoped grants.
- 2What a person may see is decided server-side from their roles and scope. UI concealment is not a permission (§08.4).
04.2.3 Simultaneity and duration
Types are held simultaneously and across decades. No surface may assume a person holds one type, and no design may assume a person's relationship began recently.
04.2.4 The person's own view
Every person can see, in plain language: what the institution holds about them, which roles they hold and in what scope, who has accessed their record under elevation and why, and what they can export or delete (§04.8).
04.3 Lifecycle
visitor ──▶ applicant ──▶ member ──▶ scholar ──▶ credentialed ──▶ alumnus
│ │ │
│ ├──▶ mentor │
│ ├──▶ advisor │
│ ├──▶ faculty │
│ └──▶ founder ──▶ investor
└──▶ dormant ◀──── returning ────▶ member
│
departed (identity severed, aggregates retained)04.3.1 Stage rules
- 1Every transition is an event (ENT-18); every transition that changes standing is an audit record (ENT-19).
- 2Dormancy is a state, not a failure. A dormant member is never pressured to return (Codex 6; §04.9).
- 3Departure severs identity and removes personal content, while preserving anonymized aggregates and the fact of issued credentials (§07).
- 4Returning after years resumes the same Person record. Nothing is re-earned that was demonstrated.
04.4 User types — the visibility contract
For each type: sees (what the surfaces show them), owns (what is theirs to control), never sees (what no scope of this type may reach). Every "never sees" is enforced server-side.
04.4.1 Public visitor
- Sees. Institutional surfaces, the Charter, published research and indexes, curriculum structure and syllabi, the glossary, credential verification results.
- Owns. Nothing; no record is created without an action they take.
- Never sees. Any member's identity, progress, submitted work, assessment, engagement, or venture material.
04.4.2 Member
- Sees. Their own record, goals, and recommendations; everything a visitor sees.
- Owns. Their profile, their goals, their consent settings, their export and deletion.
- Never sees. Another member's record, or aggregate data small enough to identify an individual (§16).
04.4.3 Scholar (student)
- Sees. Enrolled curriculum, lesson bodies, their progress, their submissions, feedback on their work, their assessments and credentials, peer work explicitly shared for review.
- Owns. Their submitted artifacts and their learning record.
- Never sees. Assessment rubrics that would invalidate an unsubmitted assessment; other scholars' grades; reviewer identities where review is blind.
04.4.4 Mentor
- Sees. Mentees' progress within the mentoring scope and what the mentee has consented to share.
- Owns. Their mentoring records and availability.
- Never sees. Mentees' data outside the mentoring scope; any mentee's financial or engagement records.
04.4.5 Faculty
- Sees. Curriculum they author or teach, cohort rosters, submissions assigned to them, assessment history relevant to a judgement they are making.
- Owns. Curriculum authorship and assessment decisions within their standard.
- Never sees. Member financial records; submissions outside their assignment without a logged elevation.
04.4.6 Reviewer
- Sees. Artifacts assigned for review, with identity withheld where review is blind.
- Owns. Their review record.
- Never sees. The author's other work, prior grades, or identity in blind review.
04.4.7 Advisor / Coach
- Sees. Their engagements, client-scoped material, commitments and risks, published research.
- Owns. Engagement records they are accountable for.
- Never sees. Other advisors' client material; any member's Academy record without that member's consent.
04.4.8 Researcher / Editor
- Sees. Sources, drafts, methodology, anonymized outcome datasets, the knowledge graph.
- Owns. Publications and methodology they author; editors own publication approval.
- Never sees. Identifiable member data. Research consumes derived, anonymized datasets only (§07).
04.4.9 Fellow
- Sees. What their appointment scope grants, typically research and curriculum surfaces.
- Owns. Their contributed work.
- Never sees. Operational member data outside the appointment scope.
04.4.10 Founder
- Sees. Their venture record, milestones, program material, investor-facing reports about their own venture.
- Owns. Their venture's submitted data.
- Never sees. Other ventures' records; investor deliberations about their venture beyond what is disclosed to them.
04.4.11 Investor
- Sees. Portfolio ventures within their investment scope and the reports agreed with them.
- Owns. Their investment records and reporting preferences.
- Never sees. Founder personal records; ventures outside their scope; any member's Academy record.
04.4.12 Enterprise client
- Sees. Their organization's cohorts and aggregate capability movement within the agreed reporting scope.
- Owns. Their organizational record and the agreed scope.
- Never sees. An individual employee's learning record, assessments, or submissions unless that individual has separately consented, and never below the aggregation threshold (§16).
04.4.13 Partner institution (university, government)
- Sees. Curriculum and credential standards, verification, and agreed aggregate reporting.
- Owns. Their organizational record and their own students' enrolment relationship where they hold it.
- Never sees. Individual records outside the agreed and consented scope; institutional financials.
04.4.14 Employee
- Sees. What their role scope grants, and nothing by virtue of employment alone.
- Owns. Their own employment and personal records.
- Never sees. Member content without a role granting it; any record without a logged reason where elevation applies.
04.4.15 Division lead
- Sees. Their division's operational and capacity reporting.
- Owns. Their division's interface commitments (§02.2.4).
- Never sees. Another division's member-level material.
04.4.16 Executive
- Sees. Institutional aggregates, targets, capacity, financial results.
- Owns. Operating decisions within doctrine (Chapter 03).
- Never sees. Individual member content by virtue of seniority. Seniority is not a scope.
04.4.17 Steward
- Sees. Doctrine, decision records, audit records, trust and commitment metrics.
- Owns. The Codices and the amendment record.
- Never sees. Member content, except through a logged elevation with a stated reason, which is itself reportable.
04.4.18 Administrator
- Sees. Role grants, access history, operational state.
- Owns. Role administration within a bounded scope.
- Never sees. Member content. Administering access is not authorisation to read what it grants.
04.4.19 Service and agent identities
- Sees. Only what their declared scope permits, never more than the subject could see themselves (§13).
- Owns. Nothing.
- Never sees. Data outside their declared purpose; consent is purpose-specific and revocable.
04.4.20 Board member
- Sees. Institutional aggregates, financial results, reserve position, risk and commitment reporting, decision records, and the doctrine.
- Owns. Nothing operational. A board member's standing is oversight, not authority over a division's work.
- Never sees. Any individual member's record, learning content, submissions, or assessments — a board seat is not a scope (§04.13.6 records what remains undecided about board decision rights).
04.4.21 Guest
- Sees. What a named invitation grants, for a stated period: a specific cohort, event, engagement, or publication under embargo.
- Owns. Their own contributed material, and the ability to end the relationship.
- Never sees. Anything outside the named invitation. Guest access expires by default; an invitation without an expiry is a defect.
04.5 Type-to-role mapping
A user type is a description; a role (ENT-05) is a grant. Surfaces and boundaries are authorised against roles and scopes, never against a type label. The types above map to role grants scoped to individual, cohort, organization, division, or institution (§08.3).
04.6 Journeys
| Journey | Stages | Chapter |
|---|---|---|
| Visitor to credentialed scholar | discovery → intake → baseline → path → enrolment → work → assessment → review → credential | WF-01, §09 |
| Credentialed to advisor | credential → eligibility → staffing → engagement → outcome → contributed case | WF-02 |
| Alumnus to mentor | credential and tenure → eligibility → training → matching → mentoring | WF-06 |
| Graduate to founder to investor | intake → program → milestones → readiness → capital → alumni | WF-04 |
| Employee of a client to scholar | organizational diagnostic → cohort → delivery → aggregate report | WF-05 |
Each journey is specified stage by stage in Chapter 09. No journey may require a person to hold two Person records at any point.
04.7 Consent
- 1Consent is explicit, purpose-specific, revocable, and recorded with a timestamp and the wording shown.
- 2Consent is never bundled into an unrelated action, and never a precondition for something it is not needed for.
- 3Revocation takes effect forward and is honoured in derived datasets at their next generation.
- 4Training an AI system on member data requires separate consent under §13, never general consent to use the service.
- 5Enterprise or partner agreements cannot consent on an individual's behalf to disclosure of their individual record.
04.8 Data rights
- 1Account. A person can see what is held about them, in plain language, without asking a human.
- 2Export. A person can export their own record and artifacts in an open format.
- 3Correction. A person can correct factual profile data; assessments and credentials are corrected only through the recorded procedure that produced them (§09).
- 4Deletion. Deletion removes personal content and severs identity, retains anonymized aggregates, and preserves the fact and validity of issued credentials, because third parties rely on verification (§10).
- 5Access transparency. A person can see elevated accesses to their record and the stated reason (§08.7).
04.9 Accessibility and treatment
- 1Accessibility is a functional requirement for every type: keyboard operability, visible focus, sufficient contrast, correct landmarks and headings, alternative text, respect for reduced motion.
- 2No type is addressed condescendingly, and no surface assumes vocabulary the institution has not taught (Codex 6).
- 3Nobody is pressured: no streak guilt, no manufactured urgency, no notification pressure, no loss framing — at any stage of the lifecycle, including dormancy and departure.
- 4Every person is addressed as themselves. Rankings of people against each other are never shown (§12).
04.10 Interfaces
ENT-01 Person, ENT-02 Identity, ENT-03 Organization, ENT-04 Membership, ENT-05 Role (Chapter 07) · API-01, API-02 (Chapter 10) · every SURF- and DASH- entry authorises against §04.5 · AGT-01..AGT-05 inherit the subject's visibility contract (§13).
04.11 Invariants
- 1One Person, for life, across every type held.
- 2Every "never sees" in §04.4 is enforced server-side, at the data layer.
- 3Seniority, employment, and administration are not scopes.
- 4Consent is purpose-specific and revocable, always.
- 5Issued credentials survive the deletion of the person's other data.
04.12 Prohibitions
- 1A second Person record for the same human, for any reason, including convenience or tenancy.
- 2Storing roles on a profile record.
- 3Deriving access from a type label rather than a role grant.
- 4Any surface that reveals one member's standing to another without consent.
- 5Aggregate reporting below the threshold that protects an individual (§16).
- 6Enterprise or partner access to an individual's record on the strength of a commercial agreement alone.
04.13 Open questions
- 1Membership classes. Whether membership tiers exist beyond role scoping, and what they entitle (§01.11.3).
- 2Minors. Whether the Academy admits people under the age of majority, and the consent and guardianship model if it does. Unresolved and blocking for any public intake to that group.
- 3Blind review scope. Which assessments are blind, and whether blindness is symmetric, is unspecified (§04.4.6).
- 4Deceased members. Handling of a Person record after death, including credential verification and memorial treatment, is undecided.
- 5Faculty employment model. As noted in §02.12.3, affects §04.4.5 scope.
- 6Board decision rights. Chapter 03 assigns decision rights entirely to the Executive and Stewardship Offices. Whether a board exists as a third body, what it may decide rather than review, and how its authority interacts with the Stewardship Office's veto, is undecided and blocking for any board-facing surface. §04.4.20 specifies only what a board member may see.
- 7Guest expiry defaults. The maximum guest invitation period, and whether renewal requires the original grantor, is unspecified (§04.4.21).
04.14 Governing Codices
Codex 1 (Article V, VI), Codex 4 (people and roles), Codex 6 (experience), Codex 5 (entities), Codex 3 (agents).