Staff: actors that run the work

Staff are named actors on the backbone. They run workflows under your org, with permission and a history.

Orkestia2 min readUpdated

Orkestia is the backbone that connects software, AI, and the real world. Staff is how you put named actors on that backbone: an org chart, roles, approval gates, inboxes, and an audit trail. A Staff actor runs the same typed workflows a person runs in the console. It does not get a side door.

The app is staff.orkestia.dev. Lifecycle is beta. Individual pages in the docs say so. The live staff.* types are in the catalog.

What you operate

Staff is the operator console for agentic staff. From the app you manage:

  • Units and actors, the org chart the work runs under
  • Roles and bindings, what an actor is allowed to start
  • Inboxes and sessions, what needs attention
  • Skills, MCP servers, and runner groups
  • Cost and organization settings
  • Audit, who did what, when, with what result

RBAC is enforced in the workflow engine through declared capabilities. A button in the Staff UI starts a workflow. An MCP call starts the same workflow. The history is one history.

How an actor runs work

The actor does not hold provider keys. Connections do. The actor starts a typed workflow with initial_data that points at a connection, the same way you would from Claude or Cursor. Failures retry on that run id. Approvals sit in front of the types you marked as needing a human.

Staff governance, in depth: Staff governance.

A typed decision in front of a Staff step is a separate connection. See Typed decisions with TypeSafe.

Seats

A Staff actor is a key seat on the published plan. A person is a user seat. The amounts are on pricing. How the model works is Billing and seats. There is nothing to negotiate.

From MCP

whoami()
list_workflow_types(prefix="staff.")
get_workflow_schema("<type>")
start_workflow(workflow_type="<type>", initial_data={...})

Read the schema. Several Staff types change org structure. They are not read-only.

Next to humans, with a paper trail

A person still opens the console. Staff does not replace them. It puts a named actor on the same workflows, under a role you can revoke without rotating a cloud key.

A useful first afternoon:

  1. Open staff.orkestia.dev.
  2. Create a unit and one actor. Bind a role that can start read-only types only.
  3. From MCP, whoami, then a staff. list. Confirm the actor you created is in the payload.
  4. Widen the role after you have watched one run's history.

Do not put provider secrets in actor env. Connections exist. TypeSafe, if you need a typed allow / block / review in front of a Staff step, is a separate post: Typed decisions with TypeSafe.

hello@orkestia.dev

  • staff
  • agents