Operators
My Access
My Access is the read-oriented experience for workers — people in the directory who are not operators (no SCIM Admin role). Full role catalog: Roles.
Operators still have My Access in the sidebar so they can verify their own expected memberships.
What workers see
- My org units — each card is one way the company is grouped (department, teams, …). A short path shows the names you sit in, with You are here on the leaf — not backend level names like division or subdepartment.
- My resources — expected memberships from resource links and pins
- Provider, resource name, role (member / owner), and which org unit (or pin) grants access
Operators see the same layout on a person’s detail page under People (third-person copy, with catalog links).
What they do not see
- Connections setup
- Resource link editor / dry-run admin tools
- Drift queues and dead-task ops
- Directory token / attribute map settings
Workers who open an admin URL are redirected to My Access.
How people get in
- IdP SCIM pushes the User (identity + optional
roles). - Active users without
Adminget Viewer access (My Access). - Users with SCIM
Adminbecome operators and see the full app. (Workspace owner is set only at signup — not via SCIM.) - Sign-in uses the same auth as operators (email code / SSO / passkeys as configured).
- My Access matches the signed-in email to the directory identity and shows the same expected access rules Camper uses for provisioning.
Empty states
| Situation | What you see |
|---|---|
| Email not in directory | Not in the directory yet — SCIM has not provisioned this address |
| Identity with no org unit | Org units empty until attributes or groups place the person |
| No resource links | Resources empty until operators attach links (or pins) |
Slack DMs (optional)
When operators enable Settings → General → Notifications, people may also get a Slack DM digest when Camper successfully adds or removes their memberships. That message is a push of what changed; My Access remains the durable view of what you should have. See Access-change notifications.