Bank Staff
People of the bank, declared on the onboarding case, who sign in through the bank's
federated identity provider. Role labels (bank-admin, maker, checker, readonly)
are descriptive; only scopes authorise API calls. Members are provisioned when the
case becomes ACTIVE. Staff members are not ledger accounts.
List staff members of an onboarding case
Lists the bank staff members declared on the case, oldest first (by `created_at`, then
Add a staff member to an onboarding case
Declares a person to be provisioned in the platform IAM when onboarding is
Get a staff member of an onboarding case
Returns one staff member with their role labels, scopes and provisioning `state`:
Update a pending staff member
Replaces the email, role labels and scopes of a staff member. All three are required;
Remove a pending staff member
Removes a staff member from the case. Nothing is removed from the platform IAM,
List the bank's staff members
Returns every staff member of the calling bank, regardless of lifecycle state. Staff are IAM principals federated through the identity provider. The collection is scoped to the caller's `bank_id`. Requires the `connector:staff:read` scope.
Add a staff member to the bank
Creates a staff member for the calling bank and enqueues identity provisioning. The member is returned in the `READY` state and transitions to `ACTIVE` once the identity provider accepts it (see the state machine in the resource `state` field).
Get one of the bank's staff members
Reads a single staff member of the calling bank. Requires the `connector:staff:read` scope.
Update one of the bank's staff members
Replaces the role labels and API scopes of an existing staff member (the email is immutable). The new values are staged and only applied once identity provisioning succeeds: the member moves to `UPDATING` (while remaining live on its previous grants) and back to `ACTIVE` on success, or to `UPDATE_FAILED` if provisioning is exhausted. `data.id` must match `staff_id` in the path.
Suspend one of the bank's staff members
Soft-deletes a staff member: it is moved to `SUSPENDING` and de-provisioned from the identity provider, reaching `DEACTIVATED` on success or `DEACTIVATION_FAILED` if de-provisioning is exhausted.