Skip to content
Stackship documentation Svenska

Access controlUsers

Built-in roles at a glance

The roles that ship with the platform, what each grants, and what each leaves out.

Built-in roles cannot be changed or deleted. They are available in every boundary, next to the boundary's custom roles. This page summarises them; a role's exact action lists are on its Permissions tab — open Access control (IAM), then Roles, then the role — and in the IAM reference in the RBAC docs, which lists every built-in role with the actions and data actions it grants.

Boundary roles

Assigned at a boundary, a resource group or a resource.

Role Grants Leaves out
Owner Every action and data action, including assigning roles, deny assignments, custom roles and approving just-in-time requests Creating and deleting boundaries, attaching boundaries to clusters, changing cluster registrations; the PostgreSQL Data Explorer data actions; reading workflow runs' step inputs and outputs
Contributor The same as Owner, minus what is listed on the right Everything Owner leaves out, and: assigning roles and managing access (rbac/members/write), adding and removing members (boundaries/members/manage), sending invitations (boundaries/invitations/create), and restoring or deleting snapshots of PostgreSQL, SQL Server and container instances
Reader Reading every resource, its members, invitations, network rules, activity and operations; reading logs of apps, static web apps, functions, jobs and container instances; opening login-protected container instance endpoints Any change; terminals, file access, secret values and database content

Because Contributor has no rbac/members/write, a Contributor cannot create custom roles or deny assignments, and cannot approve just-in-time requests.

Owner held through a group grants rbac/members/write, so it is enough to create and delete deny assignments, but not to assign roles, create custom roles or decide just-in-time requests — those need Owner assigned directly. See Who can assign roles.

Platform roles

Assigned only at the root scope /, and only by a Platform Owner. They cannot be requested as just-in-time access.

Role Grants Leaves out
Platform Owner Every action and data action, in every boundary and at the root The PostgreSQL Data Explorer data actions; reading workflow runs' step inputs and outputs
Platform Contributor The same as Platform Owner, minus what is listed on the right Deleting boundaries, moving boundaries between tenants, assigning roles and managing members and invitations, cross-tenant membership, boundary trusts, changing cluster registrations, managing platform backups, platform diagnostics
Platform Reader Reading resources in every boundary, including platform health, the Lifecycle Manager, the user directory and the registry's and S3's audit logs Any change, and every data action — no logs, secret values or content; and the reads listed below

Platform Reader's */read covers only two-part actions such as apps/read, and only some longer reads are added to it. It cannot read:

  • a boundary's members, invitations and workloads (boundaries/members/read, boundaries/invitations/read, boundaries/workloads/read);
  • deployment sources (kernel/deployments/read);
  • cluster registrations (kernel/clusters/read);
  • container instances' live status (kernel/crates/read);
  • the Kubernetes channel reads (kernel/k8sChannel/read and the other kernel/k8sChannel/* reads).

Actions that are only checked at the root are listed in Root-scoped actions.

Database Explorer

Database Explorer grants the Data Explorer on PostgreSQL and SQL Server: reading and writing rows, running queries, including queries that change data, and reading and changing schemas. It does not include dropping or truncating objects.

No other built-in role holds the PostgreSQL Data Explorer actions — Owner and Platform Owner included — so it must be assigned explicitly to anyone who is to use the Data Explorer on PostgreSQL. The SQL Server Data Explorer actions, on the other hand, are also held by Owner, Contributor, Platform Owner and Platform Contributor.

Scoped roles

Narrow roles for one area, meant for a boundary, a resource group or a single resource. Each also carries the reads the portal needs to show the resource: the boundary, its resource groups, operations, status, monitoring, Sentinel findings and search.

Role Grants
Apps Reader Viewing apps, container instances and static web apps, their pods and deployment sources
Apps Operator Creating, changing, scaling and deleting apps, container instances and static web apps; app logs and app file browsing; static web app deploys and logs
Functions Reader Viewing functions and reading their logs
Functions Operator Creating, changing, scaling and deleting functions; reading their logs
Jobs Reader Viewing jobs and reading their logs
Jobs Operator Creating, changing and deleting jobs; reading their logs
Databases Reader Viewing PostgreSQL, SQL Server, Qdrant and Valkey
Databases Operator Creating, changing and deleting those databases, and scaling PostgreSQL, SQL Server and Qdrant; snapshots of PostgreSQL and SQL Server, including restoring and deleting them; reading and changing their passwords and connection strings; SQL Server licences
Storage Reader Viewing S3 storage accounts, buckets, access keys and objects
Storage Operator Managing S3 storage accounts, buckets, access keys and objects; issuing short-lived S3 sessions
Secrets Reader Seeing vaults and reading secret values
Secrets Writer Managing vaults and reading and writing secret values
Blueprint Reader Viewing the template catalogue and the container instances deployed from it; their logs; opening their login-protected endpoints
Blueprints Operator Writing and deleting blueprint templates; managing the container instances deployed from them, including their logs, terminals and files; creating, changing and deleting vaults

Blueprints Operator's action list names secretvault/writeSecrets, but among its control-plane actions, while writing secret values is checked as a data action — so the role does not let its holder write secret values. The Secrets roles are described in more detail in Secrets permissions.

Service roles

Held by platform components rather than people.

Role Grants
Deployment Token Broker Short-lived source-repository tokens for cloning
Platform Alert Publisher Raising and clearing platform alerts
LLM Gateway Consumer Resolving registered LLM gateways, including their API key. Root scope only