Skip to content

Roles & permissions

Data-driven RBAC enforced at the API.

Seven roles, two tiers

Built-in roles cover the organization and workspace tiers. The matrix under Settings → Roles shows exactly what each role can do; permissions are enforced server-side, never just hidden in the UI.

Custom roles

Define your own roles when the built-in seven don't match a job function: name the role, tick exactly the permissions it should carry, and save. Custom roles appear in the same matrix and in the Team role pickers, are enforced server-side like the built-ins, and can be edited any time (changes apply immediately). A role can't be deleted while it's still assigned; system roles stay read-only.

Just-in-time access

Grant a user a time-boxed, per-workspace role elevation that expires automatically — least privilege without standing access. Pick the user, the workspace, the role, and a duration; duplicates are blocked, every grant and revoke is audited, and the elevation takes effect in that workspace immediately.

Try it yourself

Open the console and put this into practice.

Open the console