Access and permissions
Which permission each Platform and Apps screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (14)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Overview | Platform > Overview | Any platform role (read); a person with no platform role sees only the Capabilities list and a note |
| Packages | Platform > Packages > Packages | Any platform role (read); operator to register or sync |
| Package record | Packages > open a package | operator / release_manager / approver / config_owner per step |
| Extensions | Platform > Packages > Extensions | Any platform role (read); operator to register |
| Extension record | Extensions > open an extension | operator / release_manager / approver / config_owner |
| Releases | Platform > Releases > Releases | Any platform role (read); operator to create |
| Release record | Releases > open a release | operator (create, edit, submit, activate, recover), release_manager (stage, cancel), approver (approve, send back), config_owner (retire) |
| Environments | Platform > Releases > Environments | Any platform role (read); configuration owner to create |
| Environment record | Environments > open an environment | config_owner / approver / operator |
| Scheduled jobs | Platform > Operations > Scheduled jobs | Any platform role (read); configuration owner to create |
| Job record | Scheduled jobs > open a job | config_owner / operator |
| Job runs | Platform > Operations > Job runs | Any platform role (read); operator for the scheduler button |
| Run record | Job runs > open a run | operator |
| Restore drills | Platform > Operations > Restore drills | Any platform role (read); operator to run |
| Drill record | Restore drills > open a drill | Any platform role (read) |
| Alerts | Platform > Operations > Alerts | Any platform role (read); operator to evaluate or acknowledge |
| Workload | Platform > Operations > Workload | Any platform role (read) |
| Release readiness | Platform > Reporting > Release readiness | Any platform role (read) |
| Job health | Platform > Reporting > Job health | Any platform role (read) |
| Recovery evidence | Platform > Reporting > Recovery evidence | Any platform role (read) |
| Capabilities | Platform > Reporting > Capabilities | Any member of the company (no platform role needed) |
| Release policies | Platform > Configuration > Release policies | Any platform role (read); configuration owner to create |
| Release policy record | Release policies > open a policy | config_owner / approver |
| Alert policies | Platform > Configuration > Alert policies | Any platform role (read); configuration owner to create |
| Alert policy record | Alert policies > open a policy | config_owner / operator |
| Feature flags | Platform > Configuration > Feature flags | Any platform role (read); configuration owner to create |
| Flag record | Feature flags > open a flag | config_owner / approver |
| Vulnerability advisories | Platform > Configuration > Vulnerability advisories | Any platform role (read); release manager to import; approver to waive |
| Bills of materials | Platform > Configuration > Bills of materials | Any platform role (read); operator to take |
| SBOM record | Bills of materials > open an SBOM | Any platform role (read) |
| Platform roles | Platform > Configuration > Platform roles | Any platform role (read); only the workspace owner grants or revokes |
| Platform audit trail | Platform > Configuration > Audit trail | Any platform role (read) |
All Platform screens
| Rule | What the system does |
|---|---|
| No platform role, no console | Only the note and Capabilities show; API 403 'The platform console is for the workspace owner and people given a platform role.' |
| Workspace owner holds every role | All actions offered; an admin of only some companies is not an owner and needs a granted role |
| Role needed for each step | Each refused 'This needs the platform role 'Release manager'.' (or the named role); buttons not shown |
Platform roles
| Rule | What the system does |
|---|---|
| Only the owner grants roles | No button; API 'Only the workspace owner can grant platform roles.'; the person list is empty for non-owners |
Release record
| Rule | What the system does |
|---|---|
| Approver is independent | Refused 'Somebody other than the person who prepared this release must approve it.' - applies to superusers too |
| Signed manifest | Activation refused; signature shows INVALID |
Package record
| Rule | What the system does |
|---|---|
| Certifier is not the reviewer or registrar | Refused (separation of duties) |
Flag record
| Rule | What the system does |
|---|---|
| Proposer cannot approve | Refused 'Somebody other than the person who prepared this flag value must approve it.' |
| Protected namespaces | All refused 'That is a protected control (authorization, periods, posting, audit, approvals or tenancy). It cannot be governed by a feature flag.' |
| Protected control only tightens | 'This flag is a protected control: it can be tightened, never switched off.' / '... no company may switch it off.' |
Extension / Environment / Release policy
| Rule | What the system does |
|---|---|
| Registrar / author cannot activate or approve | Each refused 'Somebody other than the person who prepared this ... must approve it.' |
Extension record
| Rule | What the system does |
|---|---|
| Protected hook points and core fields | Refused 'That point protects access, posting, periods, audit or tenancy...' / 'An extension writes only its own registered fields, named x_acme_...' |
Environment record
| Rule | What the system does |
|---|---|
| Secrets are references only | Refused 'A secret is referenced as env:NAME, vault:path or file:path - never written here.' |
Alerts / Run record / logs
| Rule | What the system does |
|---|---|
| Redaction | Shown as 'password=[redacted]'; JWTs, sk- keys and 40+ hex secrets also masked |
Capabilities
| Rule | What the system does |
|---|---|
| Company sees only its own and no server details | B refused (not a member); A shows apps, tier label and schema yes/no only - no host, database or secret |
Health probes
| Rule | What the system does |
|---|---|
| Probes give booleans only | live -> {status: live}; ready -> status ready / not_ready (503) with database/schema/jobs booleans only |
Record screens
| Rule | What the system does |
|---|---|
| Stale revision refused | Second refused 409 'Somebody changed this record since you opened it. Reload and try again.' |
Staging
| Rule | What the system does |
|---|---|
| Staging copy does not email customers | Refused 'This is a staging copy: outgoing ... is switched off (set A2N_STAGING_OUTBOUND=1 to allow it).'; Overview banner says so |