Roles and permissions
Roles and Permissions
- Workspace owner (Admin): manage the owned workspace, tokens, members, preferences and audit. This role is assigned when creating the workspace; it does not grant installation-wide System Settings access.
- Workspace Manager: manage members (except admins), create/update/delete tokens, and update preferences within assigned workspaces; view workspace audit.
- Viewer: view tokens in assigned workspaces.
Practical guidance: invite teammates or auditors as Viewer and service owners who renew assets as Workspace Manager. Invitations and membership role changes cannot grant Admin. System administrator is a separate installation-wide privilege, not a workspace role.
Role changes are admin-only. Workspace managers can invite/remove members but cannot change admin roles.
Permission boundaries
- System Settings requires the separate system-administrator flag (
users.is_admin). Being a workspace owner or manager does not grant it. A system administrator can grant it through Workspaces → Members → System admin; see Authentication.
Next steps
- Invite and manage members after choosing a role.
- Workspaces and sections to choose an access boundary.