Roles
Every account must maintain at least one user with the role, though there is no limit to how many users can hold this role. Only an existing has the authority to remove or modify another user with this role. While all users have access to the same set of roles, those using Directory Integration or SSO must have their roles mapped.When using Directory Integration, assign each user to no more than one role group per resource—one for the account, one for each project, and one for each environment they need access to. Adding a user to multiple groups for the same resource results in inconsistent role assignment, since Directory Integration relies on SCIM group synchronization and can’t guarantee which role the user ultimately receives.
Role permissions
The four account roles, , , , and have specific permissions for the following features:Users assigned permissions prior to 15 April 2026 will continue with their individual permission configurations. These users can be migrated to the new roles model as stated above at any time by assigning them a standard role.
For more information about how to modify user roles, read Edit user roles.
