Skip to main content
A role grants:
  • inboxes: the inboxes its people see, with everything in them.
  • resources: the resources its people can search, browse and open.
  • actions: the actions they can run, on records or on their own. resource.actions["*"] grants every action on a resource, including ones added later.
  • pages: the pages in their sidebar. Everyone sees home.
  • flags: the flags they can change. Everyone can see flags.
  • reveal: whether they can reveal sensitive values.
  • status: whether they can change components and post incidents on the status page.
Roles add up: someone with two roles has everything both grant. Admins of the organization see and can do everything in its projects, and are the only ones who can delete items, manage keys and read the audit log.

Assigning roles

Invite people from the organization’s members settings, then give them roles in the project’s settings. Roles themselves only change in code, so who can do what is always in your repository and reviewed like anything else. pult diff shows who gains or loses which permission before a deploy, and a granted action that no longer exists in code simply stops working.

Agents

An agent is an API token with a role, created in the project’s settings. It works through the same permissions and leaves the same history as a person. See Console API.