Permissions and RBAC
Use workspaces and roles to separate ownership, operations, and read only access.
Workspace roles
- Admin
- Operator
- Viewer
Ownership
The workspace owner has the highest level of permissions. Only workspace owners can alter subscription settings.
Authentication and workspace roles
Workspace roles control what an authenticated user can do after signing in. Authentication controls how the user's identity is established.
Local email and password accounts can use SecuriTLS two-factor authentication on any subscription tier. Users authenticating through Single Sign-On use the authentication and multi-factor policies enforced by their configured identity provider.
Two-factor authentication and Single Sign-On do not change the Admin, Operator, or Viewer permissions assigned to the user.
Least privilege
Use roles to separate day to day operational actions from read only visibility and ownership level subscription control.