<!-- Published by AIMasterz at https://aimasterz.com/docs/templates/04-role-design.md . Part of the Company OS Method: https://aimasterz.com/docs/method -->

# Role Design — <Digital Employee name>

Stage 4 of the [method](https://aimasterz.com/docs/method). This becomes the Digital Employee manifest (contract). Design the contract before choosing how to build it.

## Role card

| Field | Value |
| --- | --- |
| Name | e.g. Digital CMO |
| Purpose | One sentence |
| Manager (approves, escalation point) | |
| Scope | Which products, accounts, regions |
| Out of scope | Explicit exclusions |
| KPIs | Outcome KPIs (business) and operating KPIs (edit rate, turnaround, failures) |
| Reports | What it produces for the manager, how often |

## Capabilities

One per process package. A capability is a process the role runs end to end.

| Capability | Process card | Trigger | Steps it executes | Steps it hands to a human | Output |
| --- | --- | --- | --- | --- | --- |

## Knowledge

| Knowledge set | Contents | Source of truth | Refresh |
| --- | --- | --- | --- |

## Connection grants

Least privilege: one resource, one mode. Installing a connection grants nothing by itself.

| System | Resource (exact account, project, property) | Mode (read / draft / act) | Why needed | Capability |
| --- | --- | --- | --- | --- |

## Approval matrix

| Action | Approver | How (bulk / per item) | Expiry | What invalidates approval |
| --- | --- | --- | --- | --- |

## Schedule

| Run | When (with time zone) | Capability | On failure |
| --- | --- | --- | --- |

## Limits and controls

| Control | Value |
| --- | --- |
| Model and budget per day/month | |
| Rate limits per connection | |
| Escalation conditions | |
| Kill switch behavior | Stop new work; stop before next side effect; reconciliation only |

## Gate

- [ ] The manager has reviewed and accepted the role card and approval matrix.
- [ ] Every connection grant names an exact resource and mode.
