> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orchestrallabs.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Identity and access

> Sign in, enroll robots and share access.

The CLI and SDK use your saved sign-in:

```bash your computer theme={null}
servo login
servo whoami
```

On a headless machine, follow the printed link and code.
`servo logout` signs out locally; `servo logout --everywhere` ends all your sign-ins.
Connect your [Hugging Face account](https://accounts.orchestrallabs.ai/account/huggingface) to import checkpoints.

## Robot identity

Python on the robot computer acts as the robot through the agent.
Enroll that computer:

```bash robot computer theme={null}
servo agent install --name yam-cell-01
```

An organization admin approves its printed code with `servo robot approve CODE --name yam-cell-01`.
`--run` keeps the robot agent running in the foreground after enrollment.
Robot registration is not required for checkpoint inference.

## Share access

Grant a person access to a robot:

<Tabs>
  <Tab title="CLI">
    ```bash your computer theme={null}
    servo access grant alice@lab.example --robot yam-cell-01 --role write
    servo access list --robot yam-cell-01
    ```
  </Tab>

  <Tab title="Python">
    Grant and list access:

    ```python your computer theme={null}
    import servo

    sv = servo.Servo()
    sv.access.grant("alice@lab.example", robot="yam-cell-01", role="write")
    print(sv.access.list(robot="yam-cell-01"))
    ```
  </Tab>
</Tabs>

| Role | Permission |
| - | - |
| `read` | Inspect robot and sessions |
| `write` | Start and stop robot sessions |
| `admin` | Grant and revoke access |

Organization admins have admin access to all robots; organization API keys retain access to all robots.
An organization member or API key can deploy and stop models.
A Google Group can replace the email after an admin connects Google Workspace; group access requires Google to be reachable.

Revoke access:

<Tabs>
  <Tab title="CLI">
    ```bash your computer theme={null}
    servo access revoke alice@lab.example --robot yam-cell-01
    ```
  </Tab>

  <Tab title="Python">
    Revoke the same grant:

    ```python your computer theme={null}
    sv.access.revoke("alice@lab.example", robot="yam-cell-01")
    ```
  </Tab>
</Tabs>

Open sessions recheck access when renewing.
An organization admin can run `servo robot remove NAME` to revoke the robot's installations while retaining its history.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.