Skip to main content
Version: 26.2

Assign a service account to a workspace

A Seqera service account has no access to anything until you assign it to a workspace with a role. Assign one when an agent or an automated job needs to act in a specific workspace.

Each assignment is direct. You grant the service account a role in one workspace at a time, and repeat that for every workspace it needs.

Prerequisites

You need the following:

Assign a workspace role​

  1. From the organization page, select Access control, then select the Service accounts tab.
  2. Select the service account.
  3. Select Edit.
  4. Under Workspace access, select Assign to workspace.
  5. Select a workspace.
  6. Select a Role. Launch is pre-selected. Owner is not offered, because a service account cannot own a workspace.
  7. Select Assign.

The service account can now act in that workspace, bounded by the role you granted.

Change a workspace role​

  1. From the Service accounts tab, select the service account.
  2. Select Edit.
  3. Under Workspace access, select the role next to the workspace.
  4. Select the new role.

The change applies as soon as you select the new role. The permission check in Role limits runs on it too.

Role limits​

You cannot grant a service account a role carrying permissions you do not hold yourself. This check runs on every workspace role assignment to a service account, and it runs once, at the moment you assign the role. Platform does not re-evaluate it later if your own permissions change.

To run an agent, a service account needs the agent:execute permission in the workspace. Every built-in role except Connect and View includes it. Platform rejects binding a service account that lacks it.

You can assign both built-in roles and custom roles to a service account.

Service accounts take workspace roles directly. Platform rejects adding one to a team. A service account therefore never inherits access the way a person in a team does.

Remove workspace access​

  1. From the Service accounts tab, select the service account.
  2. Select Edit.
  3. Under Workspace access, find the workspace.
  4. Select Remove.

The service account immediately loses its role in that workspace and can no longer act there. It remains in the organization, and its access to other workspaces is unaffected. You can re-add it to this workspace later, because removing it deletes its participation rather than the account.

caution

Removing workspace access withdraws the service account's authorization in that workspace. Its requests there start failing. Removing access does not cancel work that is already running. That work continues, failing as it goes, until it finishes or you stop it where it runs.