The roster
19 unique role names across
four team instantiations, grouped by what each is for — because the grouping is itself
the lesson about how to compose a team. 6
carry a falsifiable central claim, 7 a
descriptive one, and 6 have no
ROLE.md at all. Every count on this page is computed from
data/roster.json on every build, not typed.
A role without an exclusion list is not a role. Capability is not the constraint on
an LLM given a task — willingness is, and Not Responsible For is the only thing
that converts a capable generalist into a specialist that hands off.
The format, in full →
The portable six — start here
Architect, Dev, DevOps, Historian, Librarian, QA — defined in all three OPERATIONAL teams: Explorer, Villager, and the second product sg-playwright. the estate independently reached for these six when standing up a second product — the closest thing to a controlled experiment in the corpus. Town Planner is excluded — it is a commercial team (accountant, alchemist, designer, librarian), not an operational one.
The Architect owns the boundaries. Every interface contract, dependency direction, and abstraction layer passes through architectural review.
The entry →Dev turns architecture contracts into working, tested code. Every line follows the project's patterns. Every test uses real implementations.
The entry →DevOps owns the path from commit to production. Every deployment target works. Every deployment is smoke-tested. Every release is reproducible.
The entry →If a decision was made but its rationale is not recorded, the Historian has failed. The team will re-litigate it, wasting time and risking inconsistency.
The entry →If a piece of knowledge exists in this repo but cannot be found in under 30 seconds, the Librarian has failed.
The entry →QA owns the test matrix. Every storage mode, deployment target, and test level is covered. No release ships without QA sign-off.
The entry →Route (1)
The orchestrator that does no work.
Build (5)
The conventional core — except the Architect's claim is about boundaries, not design, and the Designer's remit runs from UI down to a CLI command's naming.
Architect
Define and guard the boundaries between components, own API contracts and data models, and ensure all technology decisions serve the zero-knowledge encryption guarantee
The entry →Dev
Implement features and fixes with high code quality, following established patterns, Type_Safe schemas, and the no-mocks testing discipline
The entry →Devops
Own the CI/CD pipelines, manage all 7 deployment targets, and ensure every push flows automatically from commit to tested deployment
The entry →Qa
Own the test strategy, maintain coverage across the full deployment matrix, and ensure every release meets quality gates before reaching users
The entry →Designer
Design is how things work — ensuring that every artifact in SG/Send communicates its purpose through its form, functions well for its audience, and expresses intention through structure, naming, formatting, and interaction
The entry →Remember (4)
The estate's real signature: four roles whose entire job is that the team can still think next month.
Librarian
Maintain knowledge connectivity across all project artifacts, ensuring every document is discoverable, cross-referenced, and current.
The entry →Historian
Track every decision, spec change, and architectural evolution so the team always knows what was decided, why it was decided, and what it superseded. Record the "why," not just the "what."
The entry →Cartographer
Map the system topology, data flows, security boundaries, and dependency relationships so that every team member can see what connects to what, what blocks what, and where the boundaries are.
The entry →Journalist
Communicate what SGraph Send is, how it works, and why it matters -- to beta users, developers, and the broader audience. Capture the present: what is happening now, what just shipped, what the team learned.
The entry →Assure (4)
Security, risk, data protection and the user's corner.
Appsec
Verify and protect the zero-knowledge guarantee -- the server never sees plaintext, never holds decryption keys, and never stores file names. Every security claim the product makes must be provably true.
The entry →Grc
Identify, assess, and manage risks to the SGraph Send project. Establish governance policies that ensure the project's security claims, operational practices, and development processes are sound, auditable, and compliant with stated commitments.
The entry →Dpo
Ensure all personal data processing is lawful, transparent, and compliant with UK GDPR, Data Protection Act 2018, and PECR. Own the legal accuracy of every privacy claim the product makes.
The entry →Advocate
No Core Mission recorded — published as a gap, not invented.
The entry →Represent (3)
Outward and onboarding-facing.
Ambassador
No Core Mission recorded — published as a gap, not invented.
The entry →Sherpa
No Core Mission recorded — published as a gap, not invented.
The entry →Translator
No Core Mission recorded — published as a gap, not invented.
The entry →Capitalise (2)
Town Planner roles: turning the estate into numbers and a narrative investors can read.