Skip to content
English
  • There are no suggestions because the search field is empty.

RBAC and Membership

Auth Service manages the role and membership information used across Governance Platform.

Organization membership controls organization-level administration. Project membership controls access to project data and project workflows.

Assign broad organization roles only to users who administer the platform. Assign Agent Operator to users who should enroll gateway agents without administering the organization. Assign project roles for normal project work.

Organization Owner

  • Permissions summary: Full organization and project administration, including users, projects, policies, indicators, declarations, reviews, credentials, settings, and agent enrollment.

Agent Operator

  • Permissions summary: Organization-level. Register gateway agents (register_agents) and view project data. Does not grant agent-to-project association.

Project Owner

  • Permissions summary: Project settings, members, applied policies, indicators, declarations, reviews, credentials, project data, and associating agents with the project.

Implementation Owner

  • Permissions summary: Create declarations, submit controls for review, and view project data.

Implementation Contributor

  • Permissions summary: Create declarations and view project data.

Audit Owner

  • Permissions summary: Record control outcomes, add review comments, manage credentials, and view project data.

Audit Contributor

  • Permissions summary: Add review comments and view project data.

Project Viewer

  • Permissions summary: View project data only.

If a user can sign in but cannot perform an action, check project membership, role assignment, and whether they are operating in the expected project.