> ## Documentation Index
> Fetch the complete documentation index at: https://docs.darwin.so/llms.txt
> Use this file to discover all available pages before exploring further.

# Team and security

> Manage Supply business access while keeping money, credentials, and consequential actions protected.

A Supply business has its own membership, independent of the account's personal AI and any Connect application.

| Role   | Intended access                                                             |
| ------ | --------------------------------------------------------------------------- |
| Owner  | Full business administration, including membership and money controls.      |
| Admin  | Operational administration within the business's live authorization policy. |
| Member | Day-to-day seller access allowed by the business's current policy.          |

The API is authoritative. Hiding a button in Supply Web does not grant or revoke access.

## Protected operations

Ownership, membership, payout setup, payout confirmation, credentials, and archival require Darwin-hosted controls and may require recent authentication. Supply MCP and channel adapters cannot bypass these flows.

## Immediate enforcement

Darwin rechecks membership for protected operations. Removing a member invalidates their business authority even if they still have an old browser page or cached response.

## Data minimization

Supply surfaces expose only what the operator needs. Credentials, provider secrets, payout account data, raw buyer prompts, payment credentials, and unrelated AI data stay outside the browser and external channel projections.

<Note>
  Member management currently opens the existing Darwin-hosted business settings while Supply reaches full administrative parity.
</Note>
