Firetower

Organise your resources

Two nouns do all the work. A team is who somebody is. A directory is which pool of things they can reach. You need both the moment those two stop being the same list, and not a minute before.

#For a solo engineer

Nothing to set up. Everything you make is born in your own space and nobody else is in it.

u/kevin

Your own space. Implicit, and not sharable by anybody.

  • mac-mini
  • backend-workspace
  • claude-subscription
No teams, no directories, no decisions.

#For small teams (2 to 5)

One team and one directory. The team is Everyone, which already exists and maintains itself, and the directory is the one pool you all work out of.

Everyoneeverybody, automaticallyd/sharedmain-workspaceclaude-subscriptioncommon-secretdev-machine
Everyone is Editor on d/shared: run on the machine, work in the workspace, use the secret, and add your own things beside them.

Everything else stays personal, and that is most of it.

u/kevin

  • laptop
  • claude-subscription
  • scratch-workspace

u/ana

  • laptop
  • codex-subscription

u/marc

  • laptop
  • linear-key
Two roots. Personal is u/<you>, shared is d/shared, and nothing in the first is reachable from the second.

Note

Give one or two people Admin on d/shared rather than all of them. An Editor can add their own things and cannot take anybody else's out, which is what stops a machine three people are working on being retired by the fourth.

#For larger teams (10 and up)

This is where one directory stops being enough, and it is not because there are more people. It is because the pools diverge: the iOS engineers need the Macs, the backend engineers need the Linux boxes, and neither needs the other's.

Two teams, three directories, and four grants.

Backend5 peopleiOS4 peopled/sharedapi-workspacegithub-secretclaude-subscriptiond/linux-machineslinux-dev-01linux-build-01backend-runnerd/apple-machinesmac-mini-01mac-mini-02ios-build-machine
Every line is Editor. Backend reaches shared and Linux; iOS reaches shared and Apple; neither reaches the other's machines.

Read it either way round, and that is the point of having two nouns:

  • One team reaches several directories. Backend is on d/shared and on d/linux-machines, which is two grants rather than a directory holding both pools and granting more than it meant to.
  • One directory is reached by several teams. d/shared is granted to Backend and to iOS, which is two grants rather than a copy of the subscription in each pool.

And everybody still has their own space, which none of this touches.

u/alice

  • laptop
  • claude-subscription

u/bob

  • laptop
  • codex-subscription
Nine people, three directories, and nine personal spaces that have never needed a decision.

#Which noun is which

A teamA directory
Answerswho somebody iswhich pool they reach
Changes whensomebody joins, leaves or movesthe infrastructure changes
Is a list ofpeoplemachines, keys, subscriptions, workspaces
You add one whena group needs granting as a groupa pool needs a different set of people

The failure this prevents is the one where the two are folded together: a directory per team, each holding a copy of the same shared things. Then adding a subscription means adding it twice, and the second copy is the one somebody forgets to rotate.

#Rules of thumb

Leave personal things personal. Laptops, subscriptions, personal API keys. There is no reason to share a subscription, and one good reason not to: whoever uses it is spending your quota.

Make a directory when a pool needs a different set of people, not when a new project starts. Four codebases worked on by the same nine people are one directory, not four.

Make a team when a group needs granting more than once. One grant does not need a team; the same three names on a third thing does.

Give Admin narrowly. Editor is "work here and add your own". Admin is "decide what happens to what is in here", including removing somebody else's.

Note

Start with d/shared and Everyone. Split it the first time you find yourself wanting to grant half of it to half of the people, and not before: a directory that was never needed is still a directory somebody has to keep granting.