Access and permissions

Which permission each Platform and Apps screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (14)

Permissions by screen

ScreenMenuPermission needed
OverviewPlatform > OverviewAny platform role (read); a person with no platform role sees only the Capabilities list and a note
PackagesPlatform > Packages > PackagesAny platform role (read); operator to register or sync
Package recordPackages > open a packageoperator / release_manager / approver / config_owner per step
ExtensionsPlatform > Packages > ExtensionsAny platform role (read); operator to register
Extension recordExtensions > open an extensionoperator / release_manager / approver / config_owner
ReleasesPlatform > Releases > ReleasesAny platform role (read); operator to create
Release recordReleases > open a releaseoperator (create, edit, submit, activate, recover), release_manager (stage, cancel), approver (approve, send back), config_owner (retire)
EnvironmentsPlatform > Releases > EnvironmentsAny platform role (read); configuration owner to create
Environment recordEnvironments > open an environmentconfig_owner / approver / operator
Scheduled jobsPlatform > Operations > Scheduled jobsAny platform role (read); configuration owner to create
Job recordScheduled jobs > open a jobconfig_owner / operator
Job runsPlatform > Operations > Job runsAny platform role (read); operator for the scheduler button
Run recordJob runs > open a runoperator
Restore drillsPlatform > Operations > Restore drillsAny platform role (read); operator to run
Drill recordRestore drills > open a drillAny platform role (read)
AlertsPlatform > Operations > AlertsAny platform role (read); operator to evaluate or acknowledge
WorkloadPlatform > Operations > WorkloadAny platform role (read)
Release readinessPlatform > Reporting > Release readinessAny platform role (read)
Job healthPlatform > Reporting > Job healthAny platform role (read)
Recovery evidencePlatform > Reporting > Recovery evidenceAny platform role (read)
CapabilitiesPlatform > Reporting > CapabilitiesAny member of the company (no platform role needed)
Release policiesPlatform > Configuration > Release policiesAny platform role (read); configuration owner to create
Release policy recordRelease policies > open a policyconfig_owner / approver
Alert policiesPlatform > Configuration > Alert policiesAny platform role (read); configuration owner to create
Alert policy recordAlert policies > open a policyconfig_owner / operator
Feature flagsPlatform > Configuration > Feature flagsAny platform role (read); configuration owner to create
Flag recordFeature flags > open a flagconfig_owner / approver
Vulnerability advisoriesPlatform > Configuration > Vulnerability advisoriesAny platform role (read); release manager to import; approver to waive
Bills of materialsPlatform > Configuration > Bills of materialsAny platform role (read); operator to take
SBOM recordBills of materials > open an SBOMAny platform role (read)
Platform rolesPlatform > Configuration > Platform rolesAny platform role (read); only the workspace owner grants or revokes
Platform audit trailPlatform > Configuration > Audit trailAny platform role (read)

All Platform screens

RuleWhat the system does
No platform role, no consoleOnly the note and Capabilities show; API 403 'The platform console is for the workspace owner and people given a platform role.'
Workspace owner holds every roleAll actions offered; an admin of only some companies is not an owner and needs a granted role
Role needed for each stepEach refused 'This needs the platform role 'Release manager'.' (or the named role); buttons not shown

Platform roles

RuleWhat the system does
Only the owner grants rolesNo button; API 'Only the workspace owner can grant platform roles.'; the person list is empty for non-owners

Release record

RuleWhat the system does
Approver is independentRefused 'Somebody other than the person who prepared this release must approve it.' - applies to superusers too
Signed manifestActivation refused; signature shows INVALID

Package record

RuleWhat the system does
Certifier is not the reviewer or registrarRefused (separation of duties)

Flag record

RuleWhat the system does
Proposer cannot approveRefused 'Somebody other than the person who prepared this flag value must approve it.'
Protected namespacesAll refused 'That is a protected control (authorization, periods, posting, audit, approvals or tenancy). It cannot be governed by a feature flag.'
Protected control only tightens'This flag is a protected control: it can be tightened, never switched off.' / '... no company may switch it off.'

Extension / Environment / Release policy

RuleWhat the system does
Registrar / author cannot activate or approveEach refused 'Somebody other than the person who prepared this ... must approve it.'

Extension record

RuleWhat the system does
Protected hook points and core fieldsRefused 'That point protects access, posting, periods, audit or tenancy...' / 'An extension writes only its own registered fields, named x_acme_...'

Environment record

RuleWhat the system does
Secrets are references onlyRefused 'A secret is referenced as env:NAME, vault:path or file:path - never written here.'

Alerts / Run record / logs

RuleWhat the system does
RedactionShown as 'password=[redacted]'; JWTs, sk- keys and 40+ hex secrets also masked

Capabilities

RuleWhat the system does
Company sees only its own and no server detailsB refused (not a member); A shows apps, tier label and schema yes/no only - no host, database or secret

Health probes

RuleWhat the system does
Probes give booleans onlylive -> {status: live}; ready -> status ready / not_ready (503) with database/schema/jobs booleans only

Record screens

RuleWhat the system does
Stale revision refusedSecond refused 409 'Somebody changed this record since you opened it. Reload and try again.'

Staging

RuleWhat the system does
Staging copy does not email customersRefused 'This is a staging copy: outgoing ... is switched off (set A2N_STAGING_OUTBOUND=1 to allow it).'; Overview banner says so