Roles and permissions
Roles and Permissions
- Admin: full control; create/rename/delete workspaces and tokens, manage members, update preferences, view audit (org + workspace). Billing changes require organization ownership. Control Center Workspace alerting (queue, eligibility, activity) is included. See Alert delivery and history.
- Workspace Manager: manage members (except admins), create/update/delete tokens, and update preferences within assigned workspaces; view workspace audit. Control Center Workspace alerting is included.
- Viewer: view tokens in assigned workspaces, including token and certificate Alerting and alert history (current eligibility and the alert timeline). Control Center alerting tabs require manager or admin.
Practical guidance: invite teammates or auditors as Viewer, and service owners who renew assets as Workspace Manager. The workspace creator holds the Admin role; the members API cannot grant Admin through an invitation or role change. Only the organization owner can manage billing.
Role changes are admin-only. Workspace managers can invite/remove members but cannot change admin roles.
Next steps
- Invite and manage members after choosing a role.
- Workspaces and sections to choose an access boundary.