diff --git a/infrastructure.md b/infrastructure.md index f243a93..fbd3d33 100644 --- a/infrastructure.md +++ b/infrastructure.md @@ -56,6 +56,32 @@ The portal database is authoritative for member emails and balances; LiteLLM's team budget is the source of truth for a member's allowance, shared between chat and API. +### The bot account on Open Collective + +You may notice **"Inference Co-op Bot"** listed as an admin of the collective on +Open Collective. This is infrastructure, not a member or a person: + +- **What it is:** a dedicated Open Collective account owned by the co-op. It + holds a **Personal Token** that the member portal uses to read membership + data — the roster, tiers (needed to route credit-pack purchases correctly), + and contributor emails (including guests, which only admins can see). +- **What it can do:** read member and tier data via Open Collective's API. + It cannot move money, issue refunds, or change the collective — Open + Collective restricts those to dashboard actions by human admins. Its API + access was verified read-mostly during the October 2026 security review. +- **Why it has admin:** reading guest contributor emails requires admin on + Open Collective; without it, membership reconciliation and credit-pack + routing can't function. +- **Who supervises it:** all of its code is open source in + [code/member-portal](https://git.inference.coop/code/member-portal) — every + API call it makes is documented there. Nathan Schneider (collective admin) + oversees its use and can revoke or rotate its token at any time from the + Open Collective dashboard. + +Nothing on Open Collective is charged, transferred, or refunded by automation: +payments always come from a human's own contribution action, and any automated +system only *reads* the resulting records. + ## The code The cooperative's software is open source, in the [`code`](https://git.inference.coop/code)