Manage access
Access administration is available from an organization’s Access menu. It manages authorization for the organization and every resource contained by it.
grant:view permits inspection. grant:manage permits creating, replacing, and revoking grants. Role creation and editing use separate role:* permissions.
Choose a starting point
The Access area provides three complementary views:
- Resources
-
Find what must be protected, then inspect or grant access to it.
- People & Teams
-
Find a principal, then inspect every direct and team-derived assignment.
- Roles
-
Inspect system roles or create reusable custom permission bundles.
Use Resources when the question is "who can operate this?" Use People & Teams when the question is "what can this person or team operate?"
Find a resource
The resource directory supports:
-
search by name, type, or complete public ID;
-
immediate filtering by resource type;
-
stable previous and next page navigation;
-
parent scope and effective assignment counts.
Open a row to see direct assignments and assignments inherited from parent scopes. An inherited assignment links back to its origin because it cannot be removed from the child resource.
Grant access
-
Choose Grant access from a resource or principal.
-
Select a user or team.
-
Select a role accepted by the target scope.
-
Choose permanent access or an expiration date.
-
Select Proceed.
-
Review the principal, role, scope, explicit permissions, and implied permissions.
-
Select Grant access.
The grant becomes active immediately and receives a stable GRA- identifier. Temporary grants stop contributing after their expiration time.
Use a parent scope
Grant a role on a parent when the same responsibility must cover its descendants. For example, assigning Project Developer on a workspace allows that principal to work with all projects and pipelines covered by the role, including compatible resources created later.
Grant on the narrowest practical scope:
-
organization for organization-wide administration;
-
workspace for a delivery environment or product portfolio;
-
project for one deployable product;
-
pipeline, repository, Registry, variable group, secret group, agent, or target for a focused responsibility.
A role can only be assigned to one of its declared scope types. Codinamo rejects incompatible role and scope combinations.
Remove access
-
Open a resource or principal detail page.
-
Find a direct assignment.
-
Select Remove access.
-
Review the role, principal, scope, and grant ID.
-
Confirm Remove access.
Revocation takes effect immediately. Access supplied by another direct grant, parent scope, or team membership remains active.
Create a custom role
-
Open Access > Roles.
-
Select Create custom role.
-
Enter a name and responsibility-focused description.
-
Select explicit permissions.
-
Select the resource types where the role may be assigned.
-
Review and save the role.
System roles provide stable defaults and cannot be edited. Duplicate a system or custom role when it is close to the required responsibility, then adjust the copy. Prefer a small number of responsibility-oriented roles over one role per person.
See How access control works for inheritance and permission implications. See Access catalog for resources, permission families, and system roles.