Skip to documentation
Early accessOpen Fork
Docs/Control plane

Control plane

Roles and permissions

Built-in roles, custom project permissions, and the limits of delegated access.

Built-in roles

RoleDefault reach
AdminManage membership, access, runtime, publishing, and organization settings.
EditorRead projects; create and edit assigned or owned branches; create commits and comments.
CommenterRead projects, branches, and commits; add comments.
ViewerRead projects, branches, and commits.

Custom roles

Administrators can define custom roles from project permissions such as view, comment, edit, fork, approve, deploy, invite, and delete. A custom role is still bounded by an Editor, Commenter, or Viewer ceiling; administrative authority is not created by combining project checkboxes.

Pending invitations protect a referenced custom role from deletion until the invitation is resolved.

Sensitive permissions

Billing management requires an administrator of the top-level organization. Application secret management is limited to the space owner, organization administrators, platform administrators, or an explicitsecrets.manage grant. Ordinary runtime access does not imply either permission.

Fork documentationBuilt from the current control plane