RBAC and Membership
Auth Service manages the role and membership information used across Governance Platform.
Membership Scope
Section titled “Membership Scope”Organization membership controls organization-level administration. Project membership controls access to project data and project workflows.
Assign broad organization roles only to users who administer the platform. Assign Agent Operator to users who should enroll gateway agents without administering the organization. Assign project roles for normal project work.
| Role | Permissions summary |
|---|---|
| Organization Owner | Full organization and project administration, including users, projects, policies, indicators, declarations, reviews, credentials, settings, and agent enrollment. |
| Agent Operator | Organization-level. Register gateway agents (register_agents) and view project data. Does not grant agent-to-project association. |
| Project Owner | Project settings, members, applied policies, indicators, declarations, reviews, credentials, project data, and associating agents with the project. |
| Implementation Owner | Create declarations, submit controls for review, and view project data. |
| Implementation Contributor | Create declarations and view project data. |
| Audit Owner | Record control outcomes, add review comments, manage credentials, and view project data. |
| Audit Contributor | Add review comments and view project data. |
| Project Viewer | View project data only. |
Troubleshooting Access
Section titled “Troubleshooting Access”If a user can sign in but cannot perform an action, check project membership, role assignment, and whether they are operating in the expected project.