Optiak Docs
Features

Roles and Access

Control who can see and manage organizations, projects, and applications.

Optiak separates organization membership from access. Adding someone as a member lets them sign in, but it does not automatically expose applications, requests, or dashboard data.

Access comes from role assignments granted directly to a person or inherited through a group.

Access Model

Optiak uses three resource levels:

Organization
└── Project
    └── Application

A role assignment applies to its selected scope and everything below it:

  • Organization-scoped roles apply across every project and application in the organization.
  • Project-scoped roles apply to every application in that project.
  • Application-scoped role assignments are not available in this version.

Every application belongs to one project. Each organization has a Default project so applications always have a project scope.

If a person receives multiple assignments, their effective access is the combination of their direct roles and roles inherited from groups.

Roles

Organization Roles

RoleWhat it allows
Organization AdminFull access to the organization, including Company Setup, members, groups, projects, applications, and all role assignments.
Workspace AdminCreate and manage projects and their applications, and grant project roles to people and groups. Cannot manage organization-level resources such as provider keys or governance.
MemberSign in to the organization. Receives no application or dashboard access until granted a project role.

Project Roles

RoleWhat it allows within the selected project
Project AdminCreate, configure, rename, and delete applications; view individual requests and operational metrics.
App AdminConfigure applications and view individual requests and operational metrics. Cannot create or delete applications.
App ViewerRead supported application configuration and operational metrics and include visible applications in dashboards. Cannot view individual requests, application credentials, or make changes.
Although they are named App Admin and App Viewer, these roles are assigned to a project and apply to every application in that project.

An App Viewer assignment by itself does not expose Modules -> Tools, because that module also requires catalog_setup:read. A user whose combined role assignments provide that permission can see Tools without gaining application mutation permissions.

Permission Summary

ActionOrganization AdminWorkspace AdminProject AdminApp AdminApp ViewerMember
Manage Company Setup and provider keys✓
Create or delete projects✓✓
Grant organization roles✓
Grant project roles✓✓
Manage groups✓
Create or delete applications✓✓✓
Configure applications✓✓✓✓
View individual requests✓✓✓✓
View supported application configuration and metrics✓✓✓✓✓
Sign in✓✓✓✓✓✓

Permissions are enforced by the backend. The UI also hides pages and actions you cannot use, but hiding a control is not the security boundary.

Members and Groups

Members

Settings -> Members controls who is enrolled in the organization. Adding a member lets that email address sign in; it does not grant access to applications.

Only Organization Admins can add or remove members.

Groups

A group is a named collection of organization members. Grant a role to a group when several people need the same access, then maintain the group membership instead of assigning each person separately.

Only Organization Admins can create, edit, delete, or change the membership of groups. Removing someone from a group removes access inherited from that group but does not affect their direct role assignments or roles inherited from other groups.

Grant Access

Open Settings -> Access to see every role assignment in the organization. Each row shows:

  • The person or group receiving access
  • The role
  • The organization or project where it applies
  • Who granted it and when

To create an assignment:

  1. Click Grant Access.
  2. Select a person or group.
  3. Select the organization or a project.
  4. Select one of the roles valid for that scope.

Organization Admins can grant organization and project roles. Workspace Admins can grant project roles only.

Use search and filters to investigate why someone can see a resource. You can also export the visible register as CSV.

Revoke Access

Revoke a role assignment from Settings -> Access. Revoking one assignment does not remove access provided by another direct assignment or group.

Optiak protects the organization from losing all administration access:

  • You cannot revoke your own Organization Admin assignment.
  • The last effective Organization Admin cannot be removed.
  • The same safeguards apply when Organization Admin access is inherited through a group.

Removing a person from Members is different from revoking a role: it removes their ability to sign in to the organization.

Visibility and Dashboards

Project and application lists contain only resources the current user can see. Dashboard and analytics queries are restricted to that same visible set, even when the client requests a broader project selection.

App Viewers can see supported application configuration and aggregate operational metrics. Individual request traces require App Admin, Project Admin, Workspace Admin, or Organization Admin access.

Copyright © 2026