[{"data":1,"prerenderedAt":645},["ShallowReactive",2],{"navigation_docs":3,"-features-roles-and-access":112,"-features-roles-and-access-surround":640},[4,26,87],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":25},"Getting Started","i-lucide-rocket","\u002Fgetting-started","1.getting-started",[10,15,20],{"title":11,"path":12,"stem":13,"icon":14},"Overview","\u002Fgetting-started\u002Foverview","1.getting-started\u002F1.overview","i-lucide-info",{"title":16,"path":17,"stem":18,"icon":19},"Platform Navigation","\u002Fgetting-started\u002Fplatform-navigation","1.getting-started\u002F2.platform-navigation","i-lucide-compass",{"title":21,"path":22,"stem":23,"icon":24},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F3.quickstart","i-lucide-play-circle",false,{"title":27,"icon":28,"path":29,"stem":30,"children":31,"page":25},"Features","i-lucide-star","\u002Ffeatures","2.features",[32,37,42,47,52,57,62,67,72,77,82],{"title":33,"path":34,"stem":35,"icon":36},"Feature Overview","\u002Ffeatures\u002Foverview","2.features\u002F01.overview","i-lucide-list",{"title":38,"path":39,"stem":40,"icon":41},"Roles and Access","\u002Ffeatures\u002Froles-and-access","2.features\u002F02.roles-and-access","i-lucide-shield-user",{"title":43,"path":44,"stem":45,"icon":46},"Company Setup","\u002Ffeatures\u002Fcompany-setup","2.features\u002F03.company-setup","i-lucide-building-2",{"title":48,"path":49,"stem":50,"icon":51},"Governance","\u002Ffeatures\u002Fgovernance","2.features\u002F04.governance","i-lucide-shield-check",{"title":53,"path":54,"stem":55,"icon":56},"Applications","\u002Ffeatures\u002Fapplications","2.features\u002F05.applications","i-lucide-box",{"title":58,"path":59,"stem":60,"icon":61},"Models and Routing","\u002Ffeatures\u002Fmodels-and-routing","2.features\u002F06.models-and-routing","i-lucide-git-branch",{"title":63,"path":64,"stem":65,"icon":66},"Context Engine","\u002Ffeatures\u002Fcontext-engine","2.features\u002F07.context-engine","i-lucide-layers",{"title":68,"path":69,"stem":70,"icon":71},"Guardrails","\u002Ffeatures\u002Fguardrails","2.features\u002F08.guardrails","i-lucide-shield-alert",{"title":73,"path":74,"stem":75,"icon":76},"Data Integrations","\u002Ffeatures\u002Fdata-integrations","2.features\u002F09.data-integrations","i-lucide-database",{"title":78,"path":79,"stem":80,"icon":81},"Tools","\u002Ffeatures\u002Ftools","2.features\u002F10.tools","i-lucide-wrench",{"title":83,"path":84,"stem":85,"icon":86},"Observability","\u002Ffeatures\u002Fobservability","2.features\u002F11.observability","i-lucide-activity",{"title":88,"icon":89,"path":90,"stem":91,"children":92,"page":25},"Integrations","i-lucide-plug","\u002Fintegrations","3.integrations",[93,98,102,107],{"title":94,"path":95,"stem":96,"icon":97},"Using the API","\u002Fintegrations\u002Fapi-usage","3.integrations\u002F3.api-usage","i-lucide-terminal-square",{"title":99,"path":100,"stem":101,"icon":89},"Test an MCP connection","\u002Fintegrations\u002Fmcp-gateway","3.integrations\u002F4.mcp-gateway",{"title":103,"path":104,"stem":105,"icon":106},"API Keys","\u002Fintegrations\u002Fapi-keys","3.integrations\u002Fapi-keys","i-lucide-key-round",{"title":108,"path":109,"stem":110,"icon":111},"Providers","\u002Fintegrations\u002Fproviders","3.integrations\u002Fproviders","i-lucide-cpu",{"id":113,"title":38,"body":114,"description":633,"extension":634,"links":635,"meta":636,"navigation":637,"path":39,"seo":638,"stem":40,"__hash__":639},"docs\u002F2.features\u002F02.roles-and-access.md",{"type":115,"value":116,"toc":616},"minimark",[117,121,129,134,137,148,151,164,171,174,178,183,233,237,280,284,295,299,494,497,501,505,511,514,518,521,524,528,535,549,552,570,573,576,580,586,589,600,606,610,613],[118,119,120],"p",{},"Optiak separates organization membership from access. Adding someone as a member lets them sign in, but it does not automatically expose applications, requests, or dashboard data.",[118,122,123,124,128],{},"Access comes from ",[125,126,127],"strong",{},"role assignments"," granted directly to a person or inherited through a group.",[130,131,133],"h2",{"id":132},"access-model","Access Model",[118,135,136],{},"Optiak uses three resource levels:",[138,139,145],"pre",{"className":140,"code":142,"language":143,"meta":144},[141],"language-text","Organization\n└── Project\n    └── Application\n","text","",[146,147,142],"code",{"__ignoreMap":144},[118,149,150],{},"A role assignment applies to its selected scope and everything below it:",[152,153,154,158,161],"ul",{},[155,156,157],"li",{},"Organization-scoped roles apply across every project and application in the organization.",[155,159,160],{},"Project-scoped roles apply to every application in that project.",[155,162,163],{},"Application-scoped role assignments are not available in this version.",[118,165,166,167,170],{},"Every application belongs to one project. Each organization has a ",[125,168,169],{},"Default"," project so applications always have a project scope.",[118,172,173],{},"If a person receives multiple assignments, their effective access is the combination of their direct roles and roles inherited from groups.",[130,175,177],{"id":176},"roles","Roles",[179,180,182],"h3",{"id":181},"organization-roles","Organization Roles",[184,185,186,199],"table",{},[187,188,189],"thead",{},[190,191,192,196],"tr",{},[193,194,195],"th",{},"Role",[193,197,198],{},"What it allows",[200,201,202,213,223],"tbody",{},[190,203,204,210],{},[205,206,207],"td",{},[125,208,209],{},"Organization Admin",[205,211,212],{},"Full access to the organization, including Company Setup, members, groups, projects, applications, and all role assignments.",[190,214,215,220],{},[205,216,217],{},[125,218,219],{},"Workspace Admin",[205,221,222],{},"Create and manage projects and their applications, and grant project roles to people and groups. Cannot manage organization-level resources such as provider keys or governance.",[190,224,225,230],{},[205,226,227],{},[125,228,229],{},"Member",[205,231,232],{},"Sign in to the organization. Receives no application or dashboard access until granted a project role.",[179,234,236],{"id":235},"project-roles","Project Roles",[184,238,239,248],{},[187,240,241],{},[190,242,243,245],{},[193,244,195],{},[193,246,247],{},"What it allows within the selected project",[200,249,250,260,270],{},[190,251,252,257],{},[205,253,254],{},[125,255,256],{},"Project Admin",[205,258,259],{},"Create, configure, rename, and delete applications; view individual requests and operational metrics.",[190,261,262,267],{},[205,263,264],{},[125,265,266],{},"App Admin",[205,268,269],{},"Configure applications and view individual requests and operational metrics. Cannot create or delete applications.",[190,271,272,277],{},[205,273,274],{},[125,275,276],{},"App Viewer",[205,278,279],{},"Read supported application configuration and operational metrics and include visible applications in dashboards. Cannot view individual requests, application credentials, or make changes.",[281,282,283],"callout",{},"Although they are named App Admin and App Viewer, these roles are assigned to a project and apply to every application in that project.",[118,285,286,287,290,291,294],{},"An App Viewer assignment by itself does not expose ",[125,288,289],{},"Modules -> Tools",", because that module also requires ",[146,292,293],{},"catalog_setup:read",". A user whose combined role assignments provide that permission can see Tools without gaining application mutation permissions.",[130,296,298],{"id":297},"permission-summary","Permission Summary",[184,300,301,321],{},[187,302,303],{},[190,304,305,308,311,313,315,317,319],{},[193,306,307],{},"Action",[193,309,209],{"align":310},"center",[193,312,219],{"align":310},[193,314,256],{"align":310},[193,316,266],{"align":310},[193,318,276],{"align":310},[193,320,229],{"align":310},[200,322,323,341,358,375,392,409,426,443,460,477],{},[190,324,325,328,331,333,335,337,339],{},[205,326,327],{},"Manage Company Setup and provider keys",[205,329,330],{"align":310},"✓",[205,332],{"align":310},[205,334],{"align":310},[205,336],{"align":310},[205,338],{"align":310},[205,340],{"align":310},[190,342,343,346,348,350,352,354,356],{},[205,344,345],{},"Create or delete projects",[205,347,330],{"align":310},[205,349,330],{"align":310},[205,351],{"align":310},[205,353],{"align":310},[205,355],{"align":310},[205,357],{"align":310},[190,359,360,363,365,367,369,371,373],{},[205,361,362],{},"Grant organization roles",[205,364,330],{"align":310},[205,366],{"align":310},[205,368],{"align":310},[205,370],{"align":310},[205,372],{"align":310},[205,374],{"align":310},[190,376,377,380,382,384,386,388,390],{},[205,378,379],{},"Grant project roles",[205,381,330],{"align":310},[205,383,330],{"align":310},[205,385],{"align":310},[205,387],{"align":310},[205,389],{"align":310},[205,391],{"align":310},[190,393,394,397,399,401,403,405,407],{},[205,395,396],{},"Manage groups",[205,398,330],{"align":310},[205,400],{"align":310},[205,402],{"align":310},[205,404],{"align":310},[205,406],{"align":310},[205,408],{"align":310},[190,410,411,414,416,418,420,422,424],{},[205,412,413],{},"Create or delete applications",[205,415,330],{"align":310},[205,417,330],{"align":310},[205,419,330],{"align":310},[205,421],{"align":310},[205,423],{"align":310},[205,425],{"align":310},[190,427,428,431,433,435,437,439,441],{},[205,429,430],{},"Configure applications",[205,432,330],{"align":310},[205,434,330],{"align":310},[205,436,330],{"align":310},[205,438,330],{"align":310},[205,440],{"align":310},[205,442],{"align":310},[190,444,445,448,450,452,454,456,458],{},[205,446,447],{},"View individual requests",[205,449,330],{"align":310},[205,451,330],{"align":310},[205,453,330],{"align":310},[205,455,330],{"align":310},[205,457],{"align":310},[205,459],{"align":310},[190,461,462,465,467,469,471,473,475],{},[205,463,464],{},"View supported application configuration and metrics",[205,466,330],{"align":310},[205,468,330],{"align":310},[205,470,330],{"align":310},[205,472,330],{"align":310},[205,474,330],{"align":310},[205,476],{"align":310},[190,478,479,482,484,486,488,490,492],{},[205,480,481],{},"Sign in",[205,483,330],{"align":310},[205,485,330],{"align":310},[205,487,330],{"align":310},[205,489,330],{"align":310},[205,491,330],{"align":310},[205,493,330],{"align":310},[118,495,496],{},"Permissions are enforced by the backend. The UI also hides pages and actions you cannot use, but hiding a control is not the security boundary.",[130,498,500],{"id":499},"members-and-groups","Members and Groups",[179,502,504],{"id":503},"members","Members",[118,506,507,510],{},[125,508,509],{},"Settings -> Members"," controls who is enrolled in the organization. Adding a member lets that email address sign in; it does not grant access to applications.",[118,512,513],{},"Only Organization Admins can add or remove members.",[179,515,517],{"id":516},"groups","Groups",[118,519,520],{},"A group is a named collection of organization members. Grant a role to a group when several people need the same access, then maintain the group membership instead of assigning each person separately.",[118,522,523],{},"Only Organization Admins can create, edit, delete, or change the membership of groups. Removing someone from a group removes access inherited from that group but does not affect their direct role assignments or roles inherited from other groups.",[130,525,527],{"id":526},"grant-access","Grant Access",[118,529,530,531,534],{},"Open ",[125,532,533],{},"Settings -> Access"," to see every role assignment in the organization. Each row shows:",[152,536,537,540,543,546],{},[155,538,539],{},"The person or group receiving access",[155,541,542],{},"The role",[155,544,545],{},"The organization or project where it applies",[155,547,548],{},"Who granted it and when",[118,550,551],{},"To create an assignment:",[553,554,555,561,564,567],"ol",{},[155,556,557,558,560],{},"Click ",[125,559,527],{},".",[155,562,563],{},"Select a person or group.",[155,565,566],{},"Select the organization or a project.",[155,568,569],{},"Select one of the roles valid for that scope.",[118,571,572],{},"Organization Admins can grant organization and project roles. Workspace Admins can grant project roles only.",[118,574,575],{},"Use search and filters to investigate why someone can see a resource. You can also export the visible register as CSV.",[130,577,579],{"id":578},"revoke-access","Revoke Access",[118,581,582,583,585],{},"Revoke a role assignment from ",[125,584,533],{},". Revoking one assignment does not remove access provided by another direct assignment or group.",[118,587,588],{},"Optiak protects the organization from losing all administration access:",[152,590,591,594,597],{},[155,592,593],{},"You cannot revoke your own Organization Admin assignment.",[155,595,596],{},"The last effective Organization Admin cannot be removed.",[155,598,599],{},"The same safeguards apply when Organization Admin access is inherited through a group.",[118,601,602,603,605],{},"Removing a person from ",[125,604,504],{}," is different from revoking a role: it removes their ability to sign in to the organization.",[130,607,609],{"id":608},"visibility-and-dashboards","Visibility and Dashboards",[118,611,612],{},"Project and application lists contain only resources the current user can see. Dashboard and analytics queries are restricted to that same visible set, even when the client requests a broader project selection.",[118,614,615],{},"App Viewers can see supported application configuration and aggregate operational metrics. Individual request traces require App Admin, Project Admin, Workspace Admin, or Organization Admin access.",{"title":144,"searchDepth":617,"depth":617,"links":618},2,[619,620,625,626,630,631,632],{"id":132,"depth":617,"text":133},{"id":176,"depth":617,"text":177,"children":621},[622,624],{"id":181,"depth":623,"text":182},3,{"id":235,"depth":623,"text":236},{"id":297,"depth":617,"text":298},{"id":499,"depth":617,"text":500,"children":627},[628,629],{"id":503,"depth":623,"text":504},{"id":516,"depth":623,"text":517},{"id":526,"depth":617,"text":527},{"id":578,"depth":617,"text":579},{"id":608,"depth":617,"text":609},"Control who can see and manage organizations, projects, and applications.","md",null,{},{"icon":41},{"title":38,"description":633},"ilrVH6i1FG_AC010Ua4irLpt-cVbbbpHz7qgu4eyvhg",[641,643],{"title":33,"path":34,"stem":35,"description":642,"icon":36,"children":-1},"Explore the core features of the Optiak platform.",{"title":43,"path":44,"stem":45,"description":644,"icon":46,"children":-1},"Organization-level setup for governance, tools, data, and models.",1791396607207]