Staff: actors that run the work
Staff are named actors on the backbone. They run workflows under your org, with permission and a history.
Orkestia2 min readUpdated
Orkestia is the backbone that connects software, AI, and the real world. Staff is how you put named actors on that backbone: an org chart, roles, approval gates, inboxes, and an audit trail. A Staff actor runs the same typed workflows a person runs in the console. It does not get a side door.
The app is staff.orkestia.dev. Lifecycle is
beta. Individual pages in the docs say so. The live staff.* types are in
the catalog.
What you operate
Staff is the operator console for agentic staff. From the app you manage:
- Units and actors, the org chart the work runs under
- Roles and bindings, what an actor is allowed to start
- Inboxes and sessions, what needs attention
- Skills, MCP servers, and runner groups
- Cost and organization settings
- Audit, who did what, when, with what result
RBAC is enforced in the workflow engine through declared capabilities. A button in the Staff UI starts a workflow. An MCP call starts the same workflow. The history is one history.
How an actor runs work
The actor does not hold provider keys. Connections do. The actor starts a
typed workflow with initial_data that points at a connection, the same way
you would from Claude or Cursor. Failures retry on that run id. Approvals
sit in front of the types you marked as needing a human.
Staff governance, in depth: Staff governance.
A typed decision in front of a Staff step is a separate connection. See Typed decisions with TypeSafe.
Seats
A Staff actor is a key seat on the published plan. A person is a user seat. The amounts are on pricing. How the model works is Billing and seats. There is nothing to negotiate.
From MCP
whoami()
list_workflow_types(prefix="staff.")
get_workflow_schema("<type>")
start_workflow(workflow_type="<type>", initial_data={...})
Read the schema. Several Staff types change org structure. They are not read-only.
Next to humans, with a paper trail
A person still opens the console. Staff does not replace them. It puts a named actor on the same workflows, under a role you can revoke without rotating a cloud key.
A useful first afternoon:
- Open staff.orkestia.dev.
- Create a unit and one actor. Bind a role that can start read-only types only.
- From MCP,
whoami, then astaff.list. Confirm the actor you created is in the payload. - Widen the role after you have watched one run's history.
Do not put provider secrets in actor env. Connections exist. TypeSafe, if you need a typed allow / block / review in front of a Staff step, is a separate post: Typed decisions with TypeSafe.
What to read next
- staff
- agents
