IRIDESC E UX · COMMAND
v30 · Program Primary Revision
INTERNALSTEP-BY-STEP

Admin & Employee Logins

Exact identity, bootstrap, role, onboarding, testing, and offboarding procedures.

Authentication vs authorization

Cloudflare Access authenticates identity. Command roles authorize actions inside Command. A person needs both: (1) an identity allowed through Access, and (2) a Command team record with the minimum role needed.

Create the first founder / Super Admin

1

Choose the exact email

Inbox

Use a mailbox controlled by one person. It can be a current work/personal-communications address during setup, but do not use a shared mailbox.

2

Set BOOTSTRAP_ADMIN_EMAIL

Command Pages → Settings → Variables and Secrets

Paste the exact email. Save.

3

Allow that same email in Access

Zero Trust → Access controls → Applications → Iridesceux Command → policy

Include → Emails → same exact email.

4

Redeploy Command

Command project → Deployments

Variables are read by the deployed Functions; use a deployment created after the change.

5

Sign in through Access

Incognito → Command hostname

Complete OTP. Then open /api/command/me.

Expected: Response shows the bootstrap email and super_admin.

Add a normal employee

1

Give the employee an individual email identity

Email/identity system

Never share an account between employees. If using OTP, the person only needs an email address that can receive the PIN.

2

Allow the exact email through Access

Access policy

Add another exact Emails selector entry or use a deliberately managed Access group. Do not broaden the policy to Everyone.

3

Add the employee inside Command

Command → Team & Access

Enter the exact same email and select the minimum role needed.

4

Test from the employee browser

Fresh private window

Have the employee authenticate, then verify they can see allowed pages and are denied restricted actions.

Command role meanings

RoleUse forDo not give it merely because…
ViewerRead-only operational visibility.They need to “see everything.”
Legal ReviewerLegal/rights/privacy workflows.They are senior.
EditorContent/site/operational editing without infrastructure control.They sometimes need a deployment.
Technical AdminTechnical configuration, Code Studio, deployments.They know how to code.
Super AdminFounders/highest-trust admins; can manage team roles and critical settings.It is more convenient.

Remove an employee completely

1

Disable the person in Command

Command → Team & Access

Set the user inactive first so Command authorization stops immediately.

2

Remove the Access permission

Zero Trust → Access policy/group

Remove the exact email/group membership.

3

Revoke/suspend the company identity

Identity provider/email

Disable the mailbox/account if employment ended.

4

Remove infrastructure/vendor access

GitHub / Cloudflare / social / finance / vendors

Remove invitations, repository access, Cloudflare membership if any, and third-party accounts.

5

Rotate anything they personally knew

Secrets

Rotate tokens/passwords/stream keys if the employee ever had direct knowledge of them.

6

Review audit logs

Command + Cloudflare

Confirm no unexpected recent actions and record the offboarding time.