Team
An Agent Service holds your agents and their building blocks; this page is about the people who work in it. A service can have members besides its owner. Membership controls what someone can do in ROC. Publishing is separate: storage writes are authorized against the bucket’s on-chain owner, so a member can push only with a token that chains back to the owner. Invite to publish gives a member that token.
Two kinds of Agent Service
| Service | Who manages people | Where |
|---|---|---|
| Personal (owned by your wallet) | You | Service ⋯ → Settings → People → Invite a member, or ⋯ → Invite member |
| Organization (owned by an organization’s vault) | The organization | People are added on the organization’s page (Members in the sidebar). The organization’s own wallet then grants publishing with Invite to publish. |
Invite someone
-
Open the service ⋯ menu → Invite to publish (organization service) or Invite member (personal service). Only the bucket’s owner sees Invite to publish.
-
Fill in the dialog:
Field Rule Member public key 0xfollowed by 64 hex characters. SS58 addresses are not accepted.Label (optional) Personal services only. Role Personal services only: developer-admin,developer-write,developer-read, orintegrator. The role sets console permissions; every member gets full bucket access. Organization invites always usedeveloper-write.Access for 1 day, 3 days, 7 days, 1 month, 1 year, or Custom date. -
Click Send invite (or Invite by link), then Copy invite link and send it.
For an organization service, only someone already in the organization with write access can accept the invite.
Accept an invite
- Open the link in the browser where you use ROC. The page reads Accept publish invite (organization) or Accept agent-service invite.
- Click Accept invite. It may ask for an on-chain transaction.
- Click Open service.
The browser keeps the invite token. You need that same browser to generate CLI tokens.
Publishing as a member
-
In the service, open ⋯ → Settings → People. In Push from the CLI, choose how long the token is valid and click Copy DDC token for the CLI. The DDC access token panel on the Access tab produces the same kind of token for you.
-
Push:
Terminal window export CEF_DDC_ACCESS_TOKEN=…cef push --bucket <bucketId> --as-pubkey <agentServicePubkey>The same token works for
cef widget pushandcef cubby push. -
Deploy with your own CLI access token from Settings → Access. It needs no invite.
“bucket belongs to other owner”
A token you minted with your own wallet cannot write an organization’s bucket: the storage node accepts only tokens rooted in the bucket’s owner. cef push checks this before uploading and stops with:
[cef] This DDC access token can't write bucket <id>: it is signed by <your address> but the bucket is owned by <owner address>. Ask the owner for "Invite to publish" in ROC (Settings → People), open the invite in your browser, then generate the token from Settings → Access.Ask the owner for Invite to publish, accept it in your browser, and generate the token again. ROC refuses to mint a DDC token for someone who is neither the owner nor holding an invite in that browser.
Publish into an organization vault
A member with write access to an organization vault’s scope can publish an agent through the vault instead of writing the bucket directly:
cef push --vault <vaultId> --vault-scope <scope> --secret-phrase "$CEF_VAULT_SECRET_PHRASE"The vault checks your write access on the scope and writes its own registry bucket. The agent’s alias is bound to the scope it is first published from. Authenticate with your wallet’s phrase or with --vault-token ($CEF_VAULT_TOKEN). --bucket, --access-token, and the network flags are refused with --vault.
Remove someone
For an organization service, remove people on the organization’s page. People still on the service’s own member list are shown on Settings → People, each with Remove.