# Your Team and Roles

> The partner portal's roles and capabilities: the read-to-admin ladder, the provisioner and finance roles beside it, operators, on call, and scoping.

*Source: https://www.whisper.security/docs/partners/team*

---
Roles decide what a colleague in your firm may do. A role is a bundle of capabilities, and a screen checks the capability rather than the role name.

## The ladder

Four roles, each holding everything the one below it holds.

### `readonly`

Reads the book and everything under it, and dispatches nothing.

### `technician`

Reads, and dispatches [response verbs](/docs/partners/respond) from a case.

### `engineer`

The security engineer. Adds tuning to what a technician reaches: the policy and detection settings a response leans on. See [policy across customers](/docs/partners/policy).

### `admin`

Everything above, plus the firm itself: people, roles and settings.

## The roles beside the ladder

Two roles sit outside the ladder and are granted on their own.

### `provisioner`

Onboards customers. [Onboard a customer](/docs/partners/onboard) is the flow it opens.

### `finance`

Reads the firm's commercial record.

## Capabilities

| capability | what it covers |
|---|---|
| `read` | the book, an estate, its detections and its record |
| `respond` | dispatching a containment verb, and running a playbook |
| `tune` | editing policy, footprint and detection settings |
| `provision` | adding a customer and taking custody of an account key |
| `money` | the firm's commercial record |
| `people` | inviting colleagues, setting roles, and scoping |

## Technicians

The people in your firm. An administrator invites a colleague, the colleague accepts, and they arrive with the role they were given. One account covers the whole of Whisper, so a colleague who already has one signs in with it.

## Operators

An operator is a technician the control plane can name individually, so an action carries a person's name rather than the firm's. Promote the people who dispatch response verbs: an action attributed to the firm is an action nobody can be asked about later. [Join a firm](/docs/partners/join) is the two-call flow that puts that authority on a key.

## On call

The rota records who is covering, so an alert reaches a person rather than a mailbox. Alert routing in [the queue](/docs/partners/queue) is set beside it.

## Access

Scoping limits which customers a person sees. A technician who covers part of the book is given that part, and the rest of the book is not rendered for them. Scoping is set by a role holding `people`, and it narrows what a colleague reaches rather than widening it.

## Brand

Your firm's logo, colour and attribution line, applied to every artifact the portal produces. Set once for the firm; [prove and report](/docs/partners/prove) is where it shows up.
