Skip to content

Documentation

Roles and permissions

Who can see what, and who can approve a change.

The roles

Owner sees everything including billing. Admin manages the workspace and its people. Member works on findings and fixes. Viewer reads. A RuahTech engineer acting on a managed ticket is a role of its own and every action they take is in your audit log under their name.

Permission is checked at the route, deny-by-default: an endpoint that names no permission is refused rather than allowed.

Delegation

You can grant somebody a role temporarily — for an incident, an audit or a holiday — with an expiry. It ends by itself, and everything done under it is marked as delegated rather than being indistinguishable from the person’s own actions.