Operators

My Access

My Access is the read-oriented experience for workers — people in the directory who are not operators (no SCIM Admin role). Full role catalog: Roles.

Operators still have My Access in the sidebar so they can verify their own expected memberships.

What workers see

  • My org units — each card is one way the company is grouped (department, teams, …). A short path shows the names you sit in, with You are here on the leaf — not backend level names like division or subdepartment.
  • My resources — expected memberships from resource links and pins
  • Provider, resource name, role (member / owner), and which org unit (or pin) grants access

Operators see the same layout on a person’s detail page under People (third-person copy, with catalog links).

What they do not see

  • Connections setup
  • Resource link editor / dry-run admin tools
  • Drift queues and dead-task ops
  • Directory token / attribute map settings

Workers who open an admin URL are redirected to My Access.

How people get in

  1. IdP SCIM pushes the User (identity + optional roles).
  2. Active users without Admin get Viewer access (My Access).
  3. Users with SCIM Admin become operators and see the full app. (Workspace owner is set only at signup — not via SCIM.)
  4. Sign-in uses the same auth as operators (email code / SSO / passkeys as configured).
  5. My Access matches the signed-in email to the directory identity and shows the same expected access rules Camper uses for provisioning.

Empty states

SituationWhat you see
Email not in directoryNot in the directory yet — SCIM has not provisioned this address
Identity with no org unitOrg units empty until attributes or groups place the person
No resource linksResources empty until operators attach links (or pins)

Slack DMs (optional)

When operators enable Settings → General → Notifications, people may also get a Slack DM digest when Camper successfully adds or removes their memberships. That message is a push of what changed; My Access remains the durable view of what you should have. See Access-change notifications.