Operator verification & continuity
Operators are the verified humans who anchor every agent’s accountability chain. Everything here happens on /dashboard/operators: getting verified, vouching for colleagues, handling continuity requests, and setting the continuity policy.
Become a verified operator
Team organizations verify their own operators through peer approval — no ID documents required. The Become a verified operator card at the top of the page walks you through it:
- Confirm your work email — verification is anchored to it.
- Click Request verification. The card switches to Waiting for a colleague to approve you with a countdown; eligible colleagues are emailed. You can Cancel request at any time.
- A colleague approves you from the approvals inbox (below). The card then reads You are a verified operator.
The founding pair. The first two email-verified members approve each other: both request verification, then each approves the other’s request — those inbox rows carry a First operators — you verify each other badge. Afterwards, any verified operator can vouch for new members. Still solo? Use the invite a teammate link to add one from /dashboard/team. Your credential then appears in the operators list further down — renew it before expiry with Re-attest; no re-approval needed.
The approvals inbox: vouching for a colleague
When someone requests verification, eligible approvers see a Colleagues waiting for your approval panel listing each request with the requester’s email and time remaining. Two choices:
- Vouch and approve — you confirm they are a real member of your organization, accountable for the agents they will operate; your name is recorded on their credential and audited.
- Decline — opens a dialog with a required Reason (required) field; confirm with Decline request. The requester sees your reason and can submit a new request.
Optional upgrade: ID verification (STRONG)
Peer approval mints a BASIC-trust credential — the chip on your card reads Peer-approved · BASIC trust — and BASIC passes every operator gate on this page. Optionally, click Upgrade to ID-verified (STRONG) on your card: a hosted government-ID + biometric check opens in a new tab, billed per check at your plan’s verification rate. Completing it raises the chip to ID-verified · STRONG trust, which the transparency auto-approval rule requires.
Personal accounts: self-attested
Personal accounts skip the ceremony: your operator credential is created automatically from your verified email, shown as Self-attested · BASIC trust. If it hasn’t appeared, confirm your email via the Verify your email button, then sign out and back in. The ID-verification upgrade above is available here too.
Transfers and co-ownership invitations
When another operator transfers an agent to you or invites you as co-owner, a Requests for you panel appears. Each request is labeled Ownership transfer or Co-ownership invitation and shows the agent’s details (purpose, framework, model, environment, enrollment date) plus the time remaining. Click Accept to become operator of record (or co-owner), or Decline to leave the agent untouched; an expired request is quietly cancelled. Accepting requires your own verified operator credential — the panel warns you if you don’t have one yet.
The adoption queue: when an operator departs
If an agent loses its last accountable operator, it suspends and lands in the Orphaned agents awaiting adoption panel, visible to org admins, with a live countdown to auto-revocation. An admin either clicks Adopt this agent — becoming its operator of record, which requires their own verified operator credential — or Deny (revoke credential), which asks for an audited reason and confirms with Deny and revoke, permanently retiring the agent. An unanswered adoption auto-revokes at the deadline — fail closed.
The continuity policy card
Admins also see the Operator continuity policy card with two settings, saved as you leave each field: Decision window (hours) (default 72) — how long adoptions, transfers, and invitations stay open — and Max operators per agent (default 1) — raise it above 1 to allow co-ownership for critical workflows that must not depend on one person.
Related: Operator continuity (the underlying anchor model and departure semantics) and Concepts: operator verification.