StaffDirectoryModule answers "who works here" in one call: one row per staff member, people and AI employees together, carrying what a colleague needs to reach them and nothing else. Staff screens and AI employees looking up a colleague call it.
Routes
/staff-directoryJWT/staff-directory/:refJWTBoth are for signed-in staff only: a caller that is not a user record — a customer, or a site visitor — gets 403 The staff directory is for staff.
- List — query
search,department,kind(people·ai),page,pageSize(default 100, max 500).searchmatches name, email, title, department, location and roles. Returnsdata,total,page,pageSizeanddepartments(the distinct departments in the result). - One —
:refis an email or a user id;404when no one matches.
What a row holds
| Field | |
|---|---|
id, email, name | From the sign-in (user) |
title, department, location, supervisor, employeeId | From the employee record, where the org keeps one |
phone | The first company phone on the user |
avatar | The user's portrait |
roles | Role and group names (bare record ids are dropped) |
status | Employment status, else user status, else active |
ai | true for an AI employee; its title comes from its ai_employee record |
A person's details are joined from their user record and, where the org runs HR, their employee record — matched by employee id, then by email. Users that are deleted or disabled are left out, and rows are sorted by name. A supervisor is shown by name, not id.
Personal and sensitive fields — home address, personal phone, SSN, date of birth, pay, emergency contacts — are never read into a row.
See also AI employees and identity and access.