Skip to content

Roles and permissions

Your Team are the people who administer the panel. (People who merely sign in to machines live under Resource Users — two separate planes.)

Role Can
Owner Everything, including billing. Every workspace has at least one.
Admin Everything except billing and deleting the workspace.
Operator Day-to-day operations: resources, people, access, policies, security actions, audit — but no team management.
Helpdesk Support tasks: view and edit people, send invitations, reset authenticators, view resources and audit.
Auditor Read-only: every view, no changes.

A role can apply to the whole workspace or be scoped to a single resource — e.g. make someone Operator of just one server. In MSP setups, roles are also assigned per customer (see MSP).

If the built-ins don’t fit, create a custom role by picking exactly the permissions it should have from the catalog (view/create/edit resources, manage access, edit people, reset authenticators, manage security blocks, view audit, manage team, settings…). Custom roles are assigned like built-ins.

The menu only shows what your role can do — a Helpdesk user simply doesn’t see Settings or Customers. If a section is “missing,” it’s a permission, not a bug.

  • The last Owner can’t be removed or downgraded — a workspace can never become ownerless.
  • Only an Owner can grant or change the Owner role.
  • Removing a team member asks for typed confirmation.
  • Every role change lands in the admin audit log.