inboxes: the inboxes its people see, with everything in them.resources: the resources its people can search, browse and open.actions: the actions they can run, on records or on their own.resource.actions["*"]grants every action on a resource, including ones added later.pages: the pages in their sidebar. Everyone sees home.flags: the flags they can change. Everyone can see flags.reveal: whether they can reveal sensitive values.status: whether they can change components and post incidents on the status page.
Assigning roles
Invite people from the organization’s members settings, then give them roles in the project’s settings. Roles themselves only change in code, so who can do what is always in your repository and reviewed like anything else.pult diff shows who gains or loses which permission before a deploy, and a granted action that no longer exists in code simply stops working.