Roles and Access
Optiak separates organization membership from access. Adding someone as a member lets them sign in, but it does not automatically expose applications, requests, or dashboard data.
Access comes from role assignments granted directly to a person or inherited through a group.
Access Model
Optiak uses three resource levels:
Organization
└── Project
└── Application
A role assignment applies to its selected scope and everything below it:
- Organization-scoped roles apply across every project and application in the organization.
- Project-scoped roles apply to every application in that project.
- Application-scoped role assignments are not available in this version.
Every application belongs to one project. Each organization has a Default project so applications always have a project scope.
If a person receives multiple assignments, their effective access is the combination of their direct roles and roles inherited from groups.
Roles
Organization Roles
| Role | What it allows |
|---|---|
| Organization Admin | Full access to the organization, including Company Setup, members, groups, projects, applications, and all role assignments. |
| Workspace Admin | Create and manage projects and their applications, and grant project roles to people and groups. Cannot manage organization-level resources such as provider keys or governance. |
| Member | Sign in to the organization. Receives no application or dashboard access until granted a project role. |
Project Roles
| Role | What it allows within the selected project |
|---|---|
| Project Admin | Create, configure, rename, and delete applications; view individual requests and operational metrics. |
| App Admin | Configure applications and view individual requests and operational metrics. Cannot create or delete applications. |
| App Viewer | Read supported application configuration and operational metrics and include visible applications in dashboards. Cannot view individual requests, application credentials, or make changes. |
An App Viewer assignment by itself does not expose Modules -> Tools, because that module also requires catalog_setup:read. A user whose combined role assignments provide that permission can see Tools without gaining application mutation permissions.
Permission Summary
| Action | Organization Admin | Workspace Admin | Project Admin | App Admin | App Viewer | Member |
|---|---|---|---|---|---|---|
| Manage Company Setup and provider keys | ✓ | |||||
| Create or delete projects | ✓ | ✓ | ||||
| Grant organization roles | ✓ | |||||
| Grant project roles | ✓ | ✓ | ||||
| Manage groups | ✓ | |||||
| Create or delete applications | ✓ | ✓ | ✓ | |||
| Configure applications | ✓ | ✓ | ✓ | ✓ | ||
| View individual requests | ✓ | ✓ | ✓ | ✓ | ||
| View supported application configuration and metrics | ✓ | ✓ | ✓ | ✓ | ✓ | |
| Sign in | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Permissions are enforced by the backend. The UI also hides pages and actions you cannot use, but hiding a control is not the security boundary.
Members and Groups
Members
Settings -> Members controls who is enrolled in the organization. Adding a member lets that email address sign in; it does not grant access to applications.
Only Organization Admins can add or remove members.
Groups
A group is a named collection of organization members. Grant a role to a group when several people need the same access, then maintain the group membership instead of assigning each person separately.
Only Organization Admins can create, edit, delete, or change the membership of groups. Removing someone from a group removes access inherited from that group but does not affect their direct role assignments or roles inherited from other groups.
Grant Access
Open Settings -> Access to see every role assignment in the organization. Each row shows:
- The person or group receiving access
- The role
- The organization or project where it applies
- Who granted it and when
To create an assignment:
- Click Grant Access.
- Select a person or group.
- Select the organization or a project.
- Select one of the roles valid for that scope.
Organization Admins can grant organization and project roles. Workspace Admins can grant project roles only.
Use search and filters to investigate why someone can see a resource. You can also export the visible register as CSV.
Revoke Access
Revoke a role assignment from Settings -> Access. Revoking one assignment does not remove access provided by another direct assignment or group.
Optiak protects the organization from losing all administration access:
- You cannot revoke your own Organization Admin assignment.
- The last effective Organization Admin cannot be removed.
- The same safeguards apply when Organization Admin access is inherited through a group.
Removing a person from Members is different from revoking a role: it removes their ability to sign in to the organization.
Visibility and Dashboards
Project and application lists contain only resources the current user can see. Dashboard and analytics queries are restricted to that same visible set, even when the client requests a broader project selection.
App Viewers can see supported application configuration and aggregate operational metrics. Individual request traces require App Admin, Project Admin, Workspace Admin, or Organization Admin access.