Core principles
- Each provider resource has one controlling community.
- Groups and experiences are different resource types even when their numeric IDs match.
- A workspace manager has no implicit network authority.
- Policy edges describe allowed relationships; drawing an edge does not execute writes.
- Network writes stay behind a separate owner-controlled safety switch.
Pilot setup
1
Add communities and resources
Add owner-controlled workspaces, then connect each Discord server, Roblox group, and required Studio experience. An experience cannot execute a group rank change.
2
Define ranks and policy
Create canonical positions and map every participating resource’s actual roles. Configure a non-staff fallback for Roblox discharge.
3
Delegate network authority
Grant network administration or independent approval to the intended people. Keep local workspace authority separate.
4
Confirm identities
Use first-party Cnect proof. Review conflicts without merging unrelated source records.
5
Simulate
Run a read-only simulation for a named person and review every current state, intended role, exception, warning, and access effect.
6
Enable the pilot
The network owner confirms the network name and enables approved writes. A simulation of the current policy revision is required.
7
Approve and canary
Distinct authorized people approve the proposal. Start with one controlled person and confirm every target read-back.
Reconciliation
The reconciliation view shows the desired revision, pinned policy, independent approvals, employment event, and every provider target. Revocations run before grants. Work for one person is serialized; unrelated people may run concurrently. The worker rechecks authority, identity, entitlement, policy revision, provider capability, and protected roles before writing.Kill switch
Turn off Allow approved network writes in Network safety to stop new target claims and later steps. An already in-flight provider request can still finish; read-back and diagnosis continue. If policy or approvals changed, cancel unfinished work only when no target is running and create a fresh simulation. Reinstatement is a new approved operation; it does not erase the discharge history.Never describe a network discharge as complete until every required target is provider-confirmed and the intended access effect has been reviewed.
Guided walkthrough

The network surface makes community resources, identity policy, and safety controls visible together.
Operating procedure
1
Inventory controlled resources
Add each community, group, and experience under exactly one controlling owner.
2
Map canonical positions
Relate local roles without erasing local provider identities.
3
Delegate separately
Grant network authority independently from workspace management.
4
Simulate the revision
Review every current and desired target for a named canary.
5
Approve and reconcile
Collect independent approval, enable writes, and verify revocations before grants.