Skip to main content
Version: 0.17

Roles and permissions

Roles and Permissions​

  • Workspace owner (Admin): manage the owned workspace, tokens, members, preferences and audit. This role is assigned when creating the workspace; it does not grant installation-wide System Settings access.
  • Workspace Manager: manage members (except admins), create/update/delete tokens, and update preferences within assigned workspaces; view workspace audit.
  • Viewer: view tokens in assigned workspaces.

Practical guidance: invite teammates or auditors as Viewer and service owners who renew assets as Workspace Manager. Invitations and membership role changes cannot grant Admin. System administrator is a separate installation-wide privilege, not a workspace role.

Role changes are admin-only. Workspace managers can invite/remove members but cannot change admin roles.

Permission boundaries​

  • System Settings requires the separate system-administrator flag (users.is_admin). Being a workspace owner or manager does not grant it. A system administrator can grant it through Workspaces → Members → System admin; see Authentication.

Next steps​