Permissions
The actions that govern boundaries, which of them only count at the root of the platform, and the roles that hold them.
Actions on a boundary
Checked on the boundary, so a role assigned on the boundary or at the root grants them.
| Action | Allows |
|---|---|
boundaries/read |
See the boundary, open its page and read its Crosslink state. Every built-in role for people includes it; the service roles the platform grants to its own components (Deployment Token Broker, Platform Alert Publisher, LLM Gateway Consumer) do not. |
boundaries/projections/read |
See which clusters the boundary is projected into. |
boundaries/network/read |
Use the Network tab: blocked connections, traffic and the reachability check. |
boundaries/manage |
Change the boundary's display name. |
crosslink/admin |
Turn Crosslink on and off, list the eligible hubs with their inbound endpoints, choose or move the hub, and rotate the boundary CA. It also gates the calls the Crosslink operators make; see the caution below. |
rbac/members/read |
See the boundary's role assignments and its tenant's single sign-on card. |
rbac/members/write |
Assign and remove roles on the boundary. |
boundaries/members/read |
List the boundary's role assignments through the boundaries API (GET /boundaries/{id}/members), which also needs rbac/members/read. |
boundaries/members/manage |
Assign roles on the boundary through the boundaries API (POST /boundaries/{id}/members) — a second way to assign them, under the same tenant rules; platform roles cannot be assigned this way. Removing an assignment through this API also needs rbac/members/write. |
boundaries/invitations/read |
See the boundary's invitations. |
boundaries/invitations/create |
Send, resend and revoke invitations to the boundary. |
Caution
crosslink/adminalso gates the API calls that the platform's Crosslink operators make on the boundary's behalf, so everyone who holds it, boundary Contributors included, can make them too:
- read the hub's link redemption code and CA certificate (
GET /boundaries/{id}/crosslink/access-grant) — a bearer secret: whoever has it can redeem it to link a site to the hub — and publish a replacement withPOSTon the same path;- list what the boundary's other clusters export (
GET /boundaries/{id}/crosslink/inventory);- overwrite the site and exposure state the operators report (
POST /boundaries/{id}/crosslink/status), which is what the Crosslink tab shows.Treat
crosslink/adminas access to the boundary's Crosslink network, not only to its settings.
Actions only granted at the root
These are checked at the root of the platform, /. A role assigned on the boundary never grants
them, even when it lists the action.
| Action | Allows |
|---|---|
boundaries/create |
Create boundaries. |
boundaries/delete |
Delete empty boundaries. |
boundaries/projections/manage |
Project a boundary into a cluster. |
boundaries/tenant/admin |
Move a boundary to another tenant. |
Roles
| Role | See, network | Rename, Crosslink | Assign roles, invite | Create, project | Delete, move tenant |
|---|---|---|---|---|---|
| Reader | Yes | No | No | No | No |
| Contributor | Yes | Yes | No | No | No |
| Owner | Yes | Yes | Yes | No | No |
| Platform Reader | Yes | No | No | No | No |
| Platform Contributor | Yes | Yes | No | Yes | No |
| Platform Owner | Yes | Yes | Yes | Yes | Yes |
The platform roles are assigned at the root and reach every boundary. Owner, Contributor and Reader are assigned on a boundary, a resource group or a resource.