Skip to main content
Eval Labs access is role-based. Evaluators receive the broader evaluator workbench; testers receive a narrower prompt-testing lane. Both roles can use saved custom suites and Keyboard Review Mode within their allowed work.

Current roles

  • owner: all declared surfaces, including Platform Runtime Registry
  • admin: privileged operations and Analysis, excluding Platform Runtime Registry
  • evaluator: evaluator workbench and own scoped evidence
  • tester: prompt-testing and own allowed evidence
  • missing or unrecognized role: protected access fails closed
Read the canonical matrix: Eval Labs Roles and Access Matrix.

Evaluator routes

Evaluators can use:
  • /
  • /keyboard-review-mode
  • /lucia/launcher
  • /lucia/custom
  • /lucia/custom/suites/:suiteId
  • /lucia/auto-generated
  • /guest-facing/verification
  • /guest-facing/verification/results
  • /lucia/batch-runner
  • /lucia/automated/runs for own scoped runs
  • /runs/:sessionId/running for an own scoped run
  • /runs/:sessionId/review for an own scoped run
  • /runs/:sessionId/review?eval=:caseId for an own scoped review item
Evaluators can save, load, delete, and deep-link reusable custom suites. They can use the Review Queue keyboard controls on a run they are already allowed to review.

Evaluator boundaries

Evaluators cannot use:
  • /analysis or /analysis/human-eval-research
  • /analysis/runs/:sessionId
  • /team-review or evaluator-detail routes
  • /registry-diagnostics
  • /platform-runtime-registry
  • /behavioral-observatory
  • the Fieldwork Communication Baseline launcher
  • cross-user evidence or owner/admin tools

Tester routes

Testers can use:
  • /
  • /keyboard-review-mode
  • /lucia/launcher
  • /lucia/custom
  • /lucia/custom/suites/:suiteId
  • /lucia/auto-generated
  • /lucia/automated/runs for own allowed runs
  • /runs/:sessionId/running for an own allowed run
  • /runs/:sessionId/review for an own allowed run
  • /runs/:sessionId/review?eval=:caseId for an own allowed review item
Testers can also save and reuse custom suites. They cannot use guest verification, Controlled Batch Runner, Fieldwork baseline, Team Review, Analysis, Registry Diagnostics, Behavioral Observatory, Human Eval Research, or Platform Runtime Registry.

Keyboard Review Mode

The reference page is available to every recognized role. Keyboard mode does not widen route or data access: it operates only inside an allowed Review Queue and preserves the same save, finalize, ownership, and durable-authorization checks.

Evidence rule

Your browser can keep compact navigation and draft state, but browser-local state is not durable cloud evidence. A review counts as persisted only after an authorized durable save succeeds. If a route that should be available is denied, ask an owner/admin to inspect the Clerk role assignment and the corresponding durable authorization decision. Do not work around the boundary.