Browse documentation

Manage access

Access administration is available from an organization’s Access menu. It manages authorization for the organization and every resource contained by it.

grant:view permits inspection. grant:manage permits creating, replacing, and revoking grants. Role creation and editing use separate role:* permissions.

Choose a starting point

The Access area provides three complementary views:

Resources

Find what must be protected, then inspect or grant access to it.

People & Teams

Find a principal, then inspect every direct and team-derived assignment.

Roles

Inspect system roles or create reusable custom permission bundles.

Use Resources when the question is "who can operate this?" Use People & Teams when the question is "what can this person or team operate?"

Find a resource

The resource directory supports:

  • search by name, type, or complete public ID;

  • immediate filtering by resource type;

  • stable previous and next page navigation;

  • parent scope and effective assignment counts.

Open a row to see direct assignments and assignments inherited from parent scopes. An inherited assignment links back to its origin because it cannot be removed from the child resource.

Grant access

  1. Choose Grant access from a resource or principal.

  2. Select a user or team.

  3. Select a role accepted by the target scope.

  4. Choose permanent access or an expiration date.

  5. Select Proceed.

  6. Review the principal, role, scope, explicit permissions, and implied permissions.

  7. Select Grant access.

The grant becomes active immediately and receives a stable GRA- identifier. Temporary grants stop contributing after their expiration time.

Use a parent scope

Grant a role on a parent when the same responsibility must cover its descendants. For example, assigning Project Developer on a workspace allows that principal to work with all projects and pipelines covered by the role, including compatible resources created later.

Grant on the narrowest practical scope:

  • organization for organization-wide administration;

  • workspace for a delivery environment or product portfolio;

  • project for one deployable product;

  • pipeline, repository, Registry, variable group, secret group, agent, or target for a focused responsibility.

A role can only be assigned to one of its declared scope types. Codinamo rejects incompatible role and scope combinations.

Remove access

  1. Open a resource or principal detail page.

  2. Find a direct assignment.

  3. Select Remove access.

  4. Review the role, principal, scope, and grant ID.

  5. Confirm Remove access.

Revocation takes effect immediately. Access supplied by another direct grant, parent scope, or team membership remains active.

Create a custom role

  1. Open Access > Roles.

  2. Select Create custom role.

  3. Enter a name and responsibility-focused description.

  4. Select explicit permissions.

  5. Select the resource types where the role may be assigned.

  6. Review and save the role.

System roles provide stable defaults and cannot be edited. Duplicate a system or custom role when it is close to the required responsibility, then adjust the copy. Prefer a small number of responsibility-oriented roles over one role per person.

See How access control works for inheritance and permission implications. See Access catalog for resources, permission families, and system roles.