User roles
Organization owners can assign role-based access levels to individual participants and teams in an organization workspace.
You can group members and collaborators into teams and apply a role to that team. Members and collaborators inherit the access role of the team.
Organization user roles
- Owner: After an organization is created, the user who created the organization is the default owner of that organization. Additional users can be assigned as organization owners. Owners have full read/write access to modify members, teams, collaborators, and settings within an organization.
- Member: A member is a user who is internal to the organization. Members have an organization role and can operate in one or more organization workspaces. In each workspace, members have a participant role that defines the permissions granted to them within that workspace.
Role inheritance
If a user is concurrently assigned to a workspace as both a named participant and member of a team, Seqera assigns the higher of the two privilege sets.
Example:
- If the participant role is Launch and the team role is Admin, the user will have Admin rights.
- If the participant role is Admin and the team role is Launch, the user will have Admin rights.
- If the participant role is Launch and the team role is Launch, the user will have Launch rights.
As a best practice, use teams as the primary vehicle for assigning rights within a workspace and only add named participants when one-off privilege escalations are necessary.
Workspace participant roles
Workspace participants with any role can leave the workspace, i.e., remove themselves as a workspace participant. However, only workspace owners and admins can add or remove workspace participants other than themselves.
Permission / Role | Owner | Admin | Maintain | Launch | Connect | View |
---|---|---|---|---|---|---|
Organization: Settings: Add, edit, delete | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Organization: Workspaces: Add, delete | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Organization: Workspaces: Edit, change visibility | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
Organization: Members: Add, delete, change role | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Organization: Teams: Add, edit, delete | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Organization: Teams: Members: Add, remove | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Organization: Teams: Workspaces: Add, remove, change role | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Organization: Collaborators: Add, edit, delete | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ |
Organization: Managed identities: Add, delete | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ |
Organization: Managed identities: Edit | ✅ | ✅ | ❌ | ❌ | ❌ |