Control plane
Roles and permissions
Built-in roles, custom project permissions, and the limits of delegated access.
Built-in roles
| Role | Default reach |
|---|---|
| Admin | Manage membership, access, runtime, publishing, and organization settings. |
| Editor | Read projects; create and edit assigned or owned branches; create commits and comments. |
| Commenter | Read projects, branches, and commits; add comments. |
| Viewer | Read projects, branches, and commits. |
Custom roles
Administrators can define custom roles from project permissions such as view, comment, edit, fork, approve, deploy, invite, and delete. A custom role is still bounded by an Editor, Commenter, or Viewer ceiling; administrative authority is not created by combining project checkboxes.
Pending invitations protect a referenced custom role from deletion until the invitation is resolved.
Sensitive permissions
Billing management requires an administrator of the top-level organization. Application secret management is limited to the space owner, organization administrators, platform administrators, or an explicitsecrets.manage grant. Ordinary runtime access does not imply either permission.