Part of #884. Strategy §2.5. The authoring UX over the roster — joiner/mover/leaver as a form, not hand-edited YAML. Can follow P1.3/P1.4; not blocking.
Scope
- Scaffolder templates that emit
gitops/people/<name>.yaml PRs (add / change-grant / remove) — propose, never grant; the gate authorizes.
- Form-time validation (team + role from the registries); Backstage RBAC scopes who can see the templates.
- Off the template path: temporary-power activation (fast controller action, P3) and identity linking (the OAuth "Connect your accounts" flow, ADR-084).
Done when: a team-admin can onboard/offboard a person via the portal → a gated PR.
Part of #884. Strategy §2.5. The authoring UX over the roster — joiner/mover/leaver as a form, not hand-edited YAML. Can follow P1.3/P1.4; not blocking.
Scope
gitops/people/<name>.yamlPRs (add / change-grant / remove) — propose, never grant; the gate authorizes.Done when: a team-admin can onboard/offboard a person via the portal → a gated PR.