Roles and permissions
Your Team are the people who administer the panel. (People who merely sign in to machines live under Resource Users — two separate planes.)
Built-in roles
Section titled “Built-in roles”| Role | Can |
|---|---|
| Owner | Everything, including billing. Every workspace has at least one. |
| Admin | Everything except billing and deleting the workspace. |
| Operator | Day-to-day operations: resources, people, access, policies, security actions, audit — but no team management. |
| Helpdesk | Support tasks: view and edit people, send invitations, reset authenticators, view resources and audit. |
| Auditor | Read-only: every view, no changes. |
Scope: workspace or one resource
Section titled “Scope: workspace or one resource”A role can apply to the whole workspace or be scoped to a single resource — e.g. make someone Operator of just one server. In MSP setups, roles are also assigned per customer (see MSP).
Custom roles
Section titled “Custom roles”If the built-ins don’t fit, create a custom role by picking exactly the permissions it should have from the catalog (view/create/edit resources, manage access, edit people, reset authenticators, manage security blocks, view audit, manage team, settings…). Custom roles are assigned like built-ins.
Progressive disclosure
Section titled “Progressive disclosure”The menu only shows what your role can do — a Helpdesk user simply doesn’t see Settings or Customers. If a section is “missing,” it’s a permission, not a bug.
Guardrails
Section titled “Guardrails”- The last Owner can’t be removed or downgraded — a workspace can never become ownerless.
- Only an Owner can grant or change the Owner role.
- Removing a team member asks for typed confirmation.
- Every role change lands in the admin audit log.