Operators
Roles & permissions
How people get elevated from your IdP, the full role catalog, and setup guidance live under Directory: Roles.
This page is the short in-app view: who sees what after they sign in.
At a glance
| Role | How they get it | In the product |
|---|---|---|
| Owner | Created the workspace | Full operator UI + ownership |
| Admin | IdP sends SCIM Admin, or bootstrap invite | Full operator UI |
| Viewer | Default for SCIM users (or explicit Viewer) | My Access + own account settings |
One login can belong to several workspaces with a different role in each.
Owner is not set from the IdP. Map operators to Admin only — see Roles.
Operators vs workers
- Operators (owner / admin) see the full sidebar: Catalog, People, Resources, Activity, Connections, Settings.
- Workers (viewer) see My Access — “what access do I have?” — plus their own account security settings.
After SCIM and SSO are both configured, the People page hides operator invites so elevation stays in the IdP. See People.
What requires an operator
Actions that change the workspace (mint a SCIM token, connect an app, link a resource, retry failed tasks, invite someone, change billing settings, …) need owner or admin. A viewer session cannot perform those actions.
Sessions
Under Account settings → Active sessions you can:
- See devices signed in with your account
- Revoke a single session
- Revoke others (sign out every device except this one)
Deactivating someone via SCIM also ends their sessions for this workspace. See Account security.