Role-Based Access Control
Role-Based Access Control
Role-Based Access Control
Available to Enterprise Plan customers only.
Role-based access control (RBAC) lets you grant the right level of access to each teammate while keeping sensitive account actions limited to trusted users. RBAC grants permissions through roles, and every member can hold multiple assignments across the account and individual projects.
RBAC permissions are evaluated at two scopes:
Authorizations are grouped into the following capability areas. These appear in the dashboard when you review role details.
account.view.readonly — View account-level configuration, billing status, and usage.rbac.account.manage — Create, update, or delete account-scoped role assignments, including promoting additional Account Owners.rbac.project.manage — Manage project-scoped assignments and project-level resources (API keys, data ingestion, deletion) for the projects a member administers.The role catalog includes account-wide roles and project-scoped roles. Assignments can be combined so that, for example, a teammate can be an Account Admin and a Project Viewer on a sensitive project.