<!--
Sitemap:
- [Installation](/installation)
- [Upgrading](/upgrading): Version-specific steps for upgrading an existing Bento install.
- [Concepts](/concepts)
- [Build your first pipeline](/tutorials/pipeline-args)
- [Target a specific issue or PR from a URL](/tutorials/url-targeting)
- [Keep state across runs](/tutorials/pipeline-state)
- [Fire a pipeline on a schedule or on demand](/tutorials/schedule-and-fire)
- [Deploy a box to Railway](/tutorials/deploy-to-railway)
- [Operate a hosted daemon](/tutorials/operate-a-hosted-daemon)
- [Configuration](/configuration)
- [Members](/members)
- [Knowledge base](/knowledge-base/)
- [Method and delivery](/knowledge-base/modes)
- [Config](/knowledge-base/config)
- [MCP](/knowledge-base/mcp)
- [Pipeline configuration reference](/pipelines/config)
- [Filters](/pipelines/filters)
- [Triggers](/triggers/)
- [GitHub trigger](/triggers/github)
- [Linear trigger](/triggers/linear)
- [Webhook trigger](/triggers/webhook)
- [Schedule trigger](/triggers/schedule)
- [Manual trigger](/triggers/manual)
- [Traces](/pipelines/traces)
- [Slack](/integrations/slack)
- [Public access](/public-access)
- [Context engineering](/context-engineering)
- [Best practices](/best-practices)
- [Troubleshooting](/troubleshooting)
- [Architecture](/architecture/vision)
- [Workspaces](/workspaces)
- [Authentication](/authentication)
- [Identity](/identity)
- [Security](/security)
- [References](/references)
- [Changelog](/changelog): Bento release history.
- [CLI reference](/cli/)
- [Setup](/cli/setup)
- [Secrets](/cli/secrets)
- [Lifecycle](/cli/lifecycle)
- [Sandbox image](/cli/image)
- [Sandboxes](/cli/sandbox)
- [Observability](/cli/observability)
- [Diagnostics](/cli/diagnostics)
- [Triggers](/cli/triggers)
- [Workbench](/cli/workbench)
- [Auth](/cli/auth)
- [Knowledge](/cli/knowledge)
- [Evals](/cli/evals)
- [Bento](/index)
- [Runtime wrapper](/architecture/runtime-wrapper)
- [Skill evolve](/architecture/skill-evolve)
-->

# Members

Use `.bento/members.yaml` to maintain the people, agents, and services that Bento addresses. This page describes the manual member directory for Self-Hosted deployments.

> **Bento Cloud:** Cloud-managed member directories are coming soon. Until then, maintain `.bento/members.yaml` in your Self-Hosted project.

## Create a member directory

Add one entry for each member that Bento must resolve. Use a stable member key and at least one provider identity.

```yaml
members:
  arnold:
    name: Arnold Porter
    kind: person
    identities:
      github:
        id: "42714653"
        handle: arnoldporter
      slack:
        id: U04AB12CD
```

## Maintain identities

Use the provider account `id` for routing. Keep the `id` when a person changes their provider handle.

Use `handle` as a readable alias and as a fallback for webhook payloads that contain no provider ID. A handle can change without changing the member key or provider ID.

Supported providers are `github`, `slack`, and `linear`. Each identity needs a non-empty provider `id`.

Use `kind` to describe the entry. The default is `person`.

| `kind` | Use for |
| --- | --- |
| `person` | A person who can answer an eval. |
| `agent` | An agent that Bento knows but does not ask for an eval. |
| `service` | A service identity that Bento does not ask for an eval. |

Set `status: deactivated` when a person should not receive new eval requests. Keep the entry so that historical references still resolve.

## Create groups

Use `.bento/groups.yaml` to define named sets of members.

```yaml
groups:
  reviewers:
    members: [arnold]
```

Reference member keys in groups. Do not use handles. Groups contain member keys, not other groups.

## Validate the directory

Run the configuration validator after you add, rename, deactivate, or remove a member:

```bash
bento config validate
```

The validator checks member identities, duplicate provider IDs, duplicate handles, group membership, and literal eval recipients. It also checks the result-field paths in `eval.of` and `eval.labels` against a declared `result.schema`.

## Use members in evals

An `eval.of` value can name a member key, a member handle, a provider account ID, or a group:

```yaml
eval:
  of: arnold
```

See the [pipeline eval reference](/pipelines/config#eval) for recipient and result-based routing.
