Operators

Roles & permissions

How people get elevated from your IdP, the full role catalog, and setup guidance live under Directory: Roles.

This page is the short in-app view: who sees what after they sign in.

At a glance

RoleHow they get itIn the product
OwnerCreated the workspaceFull operator UI + ownership
AdminIdP sends SCIM Admin, or bootstrap inviteFull operator UI
ViewerDefault for SCIM users (or explicit Viewer)My Access + own account settings

One login can belong to several workspaces with a different role in each.

Owner is not set from the IdP. Map operators to Admin only — see Roles.

Operators vs workers

  • Operators (owner / admin) see the full sidebar: Catalog, People, Resources, Activity, Connections, Settings.
  • Workers (viewer) see My Access — “what access do I have?” — plus their own account security settings.

After SCIM and SSO are both configured, the People page hides operator invites so elevation stays in the IdP. See People.

What requires an operator

Actions that change the workspace (mint a SCIM token, connect an app, link a resource, retry failed tasks, invite someone, change billing settings, …) need owner or admin. A viewer session cannot perform those actions.

Sessions

Under Account settings → Active sessions you can:

  • See devices signed in with your account
  • Revoke a single session
  • Revoke others (sign out every device except this one)

Deactivating someone via SCIM also ends their sessions for this workspace. See Account security.