Manage Access

Invite people, assign scoped roles, manage groups, edit roles, and audit changes.

Open Organization Settings → Access to manage authorization. The hub has up to four tabs, shown according to your effective governance permissions.

TabPurpose
PeopleInvite members, inspect their access, assign or revoke roles, and remove members
GroupsManage group membership and bind roles to a group at organization or workspace scope
RolesCreate and edit roles, catalog grants, inheritance, assignments, and impact previews
ActivityReview authorization changes, actors, targets, and policy decisions

The Roles and Activity tabs require full access authority. People and Groups can be available to narrower custom governance roles. Groups require the Access Control entitlement; direct person assignments remain available without it.

Invite a person with a role

  1. Open Access → People.
  2. Enter the person's email address.
  3. Choose a seeded or custom role.
  4. Send the invitation.

The invitation stores the role key. When accepted, SteelEngine creates the matching assignment instead of translating the choice into a fixed access tier.

Assign a role to an existing person

  1. Select the person in Access → People.
  2. Open the assignment control in the person drawer.
  3. Choose a role.
  4. Choose Entire organization or one workspace.
  5. Confirm the assignment.

Use organization scope only when the person should receive that role anywhere its permissions apply. For a project-specific responsibility, choose a workspace.

Inspect why someone has access

The person drawer combines the access inspector and assignment controls. Select a workspace to answer:

  • Which roles apply here?
  • Is each role direct, organization-wide, or inherited through a group?
  • Which catalog permissions does each role contribute?
  • Which inheritance path produced a permission?

This is the authoritative place to investigate “why can this person do this?”

Create or edit a role

  1. Open Access → Roles.
  2. Select an existing role or create a custom role.
  3. Add permissions from the Permission Catalog.
  4. Choose organization or workspace scope for each grant when offered.
  5. Add inherited roles if the role should reuse an existing permission set.
  6. Review the impact preview.
  7. Save.

The impact preview distinguishes assignments from effective change. A person may already receive a permission through another role, so removing one grant does not necessarily remove their effective access.

Use groups

Groups make repeated assignment easier:

  1. Create a group such as Contractors or Data Operations.
  2. Add organization members to the group.
  3. Assign a role to the group.
  4. Choose organization or workspace scope.

Members inherit the group's assignment. Adding or removing a member changes their effective access without editing the role or duplicating person assignments.

Direct and group assignments are additive. Removing a person from a group removes only that group's path; another direct, group, or organization-wide assignment can still grant the same permission.

Remove access safely

Before revoking a role or removing a member, inspect all provenance paths. SteelEngine removes a departed member's organization-wide and workspace-scoped role assignments as part of organization removal.

Sensitive changes are protected by a lockout guardrail. A change is rejected when it would leave no remaining organization member able to manage both authorization and membership.

  1. Keep the seeded roles as broad defaults.
  2. Create custom roles for repeated job functions.
  3. Prefer workspace scope for project responsibilities.
  4. Use groups when several people share the same assignment.
  5. Inspect effective access before removing a grant.
  6. Review Activity after high-impact changes.

On this page