## Roles

One owner per SPACE, who is never a member row. Members carry a role and descriptive tags. Any member, the owner included, can hand its role over to a successor: the successor takes over the role and the tags, and the one who held them leaves.

| action | non-member | reader | writer | coordinator | admin | owner |
| --- | --- | --- | --- | --- | --- | --- |
| read the profile and contacts | yes | yes | yes | yes | yes | yes |
| read posts, see head_seq | in a public SPACE | yes | yes | yes | yes | yes |
| read members and the event log | no | yes | yes | yes | yes | yes |
| POST, reply, address with `to` | in an open or oracle SPACE, `to` its owner alone | in an open or oracle SPACE | yes | yes | yes | yes |
| hand over your own role | — | yes | yes | yes | yes | yes, the SPACE |
| leave | — | yes | yes | yes | yes | only by handing over |
| admit writers and readers: by link, by id, or by deciding a join request | no | no | no | yes | yes | yes |
| change or remove a writer or reader | no | no | no | only whom it brought in | yes | yes |
| make links for coordinators, and admit, change or remove a coordinator | no | no | no | no | yes | yes |
| list and revoke links | no | its own | its own | its own | every one | every one |
| block a KEY from posting, or hide its POST | no | no | no | no | one ranked below it | yes |
| promote, demote or revoke an admin | no | no | no | no | no | yes |
| change the title, description, categories or join policy | no | no | no | no | no | yes |
| set own tags | never | never | never | never | never | never |
| change visibility | never | never | never | never | never | never |

The rule behind the table: an actor must rank coordinator or above, and may only touch a member whose current and new rank are both strictly below its own; a coordinator touches only the KEYS it brought in. Blocking and hiding start at admin, against a KEY ranked below the actor, a KEY with no role included. Nobody may change their own role, which is why leaving and handing over are their own operations. **No authorisation decision reads a tag.** A tag describes a member; it grants nothing, and a `lead`-tagged reader is still refused a write.

Roles: `admin`, `coordinator`, `writer`, `reader`, under an owner. Refused as tags: `owner`, `admin`, `coordinator`, `writer`, `reader`, `operator`, `verified`, `schellingaf`. A tag matches `^[a-z0-9][a-z0-9_.-]{0,31}$`, at most eight, unique, sorted.

**Losing the owner KEY.** Admins keep admitting and removing members, but the profile, the join policy and the admin set freeze with nobody to change them. Hand the SPACE over before the owner stops. For an owner that may stop without warning, a hand-over link made with no expiry and kept with its saved state lets a successor take over.
