Admin & Employee Logins
Exact identity, bootstrap, role, onboarding, testing, and offboarding procedures.
Authentication vs authorization
Cloudflare Access authenticates identity. Command roles authorize actions inside Command. A person needs both: (1) an identity allowed through Access, and (2) a Command team record with the minimum role needed.
Create the first founder / Super Admin
Choose the exact email
InboxUse a mailbox controlled by one person. It can be a current work/personal-communications address during setup, but do not use a shared mailbox.
Set BOOTSTRAP_ADMIN_EMAIL
Command Pages → Settings → Variables and SecretsPaste the exact email. Save.
Allow that same email in Access
Zero Trust → Access controls → Applications → Iridesceux Command → policyInclude → Emails → same exact email.
Redeploy Command
Command project → DeploymentsVariables are read by the deployed Functions; use a deployment created after the change.
Sign in through Access
Incognito → Command hostnameComplete OTP. Then open /api/command/me.
super_admin.Add a normal employee
Give the employee an individual email identity
Email/identity systemNever share an account between employees. If using OTP, the person only needs an email address that can receive the PIN.
Allow the exact email through Access
Access policyAdd another exact Emails selector entry or use a deliberately managed Access group. Do not broaden the policy to Everyone.
Add the employee inside Command
Command → Team & AccessEnter the exact same email and select the minimum role needed.
Test from the employee browser
Fresh private windowHave the employee authenticate, then verify they can see allowed pages and are denied restricted actions.
Command role meanings
| Role | Use for | Do not give it merely because… |
|---|---|---|
| Viewer | Read-only operational visibility. | They need to “see everything.” |
| Legal Reviewer | Legal/rights/privacy workflows. | They are senior. |
| Editor | Content/site/operational editing without infrastructure control. | They sometimes need a deployment. |
| Technical Admin | Technical configuration, Code Studio, deployments. | They know how to code. |
| Super Admin | Founders/highest-trust admins; can manage team roles and critical settings. | It is more convenient. |
Remove an employee completely
Disable the person in Command
Command → Team & AccessSet the user inactive first so Command authorization stops immediately.
Remove the Access permission
Zero Trust → Access policy/groupRemove the exact email/group membership.
Revoke/suspend the company identity
Identity provider/emailDisable the mailbox/account if employment ended.
Remove infrastructure/vendor access
GitHub / Cloudflare / social / finance / vendorsRemove invitations, repository access, Cloudflare membership if any, and third-party accounts.
Rotate anything they personally knew
SecretsRotate tokens/passwords/stream keys if the employee ever had direct knowledge of them.
Review audit logs
Command + CloudflareConfirm no unexpected recent actions and record the offboarding time.