Open Organization Settings → Access to manage authorization. The hub has up to four tabs, shown according to your effective governance permissions.
| Tab | Purpose |
|---|---|
| People | Invite members, inspect their access, assign or revoke roles, and remove members |
| Groups | Manage group membership and bind roles to a group at organization or workspace scope |
| Roles | Create and edit roles, catalog grants, inheritance, assignments, and impact previews |
| Activity | Review authorization changes, actors, targets, and policy decisions |
The Roles and Activity tabs require full access authority. People and Groups can be available to narrower custom governance roles. Groups require the Access Control entitlement; direct person assignments remain available without it.
Invite a person with a role
- Open Access → People.
- Enter the person's email address.
- Choose a seeded or custom role.
- Send the invitation.
The invitation stores the role key. When accepted, SteelEngine creates the matching assignment instead of translating the choice into a fixed access tier.
Assign a role to an existing person
- Select the person in Access → People.
- Open the assignment control in the person drawer.
- Choose a role.
- Choose Entire organization or one workspace.
- Confirm the assignment.
Use organization scope only when the person should receive that role anywhere its permissions apply. For a project-specific responsibility, choose a workspace.
Inspect why someone has access
The person drawer combines the access inspector and assignment controls. Select a workspace to answer:
- Which roles apply here?
- Is each role direct, organization-wide, or inherited through a group?
- Which catalog permissions does each role contribute?
- Which inheritance path produced a permission?
This is the authoritative place to investigate “why can this person do this?”
Create or edit a role
- Open Access → Roles.
- Select an existing role or create a custom role.
- Add permissions from the Permission Catalog.
- Choose organization or workspace scope for each grant when offered.
- Add inherited roles if the role should reuse an existing permission set.
- Review the impact preview.
- Save.
The impact preview distinguishes assignments from effective change. A person may already receive a permission through another role, so removing one grant does not necessarily remove their effective access.
Use groups
Groups make repeated assignment easier:
- Create a group such as Contractors or Data Operations.
- Add organization members to the group.
- Assign a role to the group.
- Choose organization or workspace scope.
Members inherit the group's assignment. Adding or removing a member changes their effective access without editing the role or duplicating person assignments.
Direct and group assignments are additive. Removing a person from a group removes only that group's path; another direct, group, or organization-wide assignment can still grant the same permission.
Remove access safely
Before revoking a role or removing a member, inspect all provenance paths. SteelEngine removes a departed member's organization-wide and workspace-scoped role assignments as part of organization removal.
Sensitive changes are protected by a lockout guardrail. A change is rejected when it would leave no remaining organization member able to manage both authorization and membership.
Recommended operating pattern
- Keep the seeded roles as broad defaults.
- Create custom roles for repeated job functions.
- Prefer workspace scope for project responsibilities.
- Use groups when several people share the same assignment.
- Inspect effective access before removing a grant.
- Review Activity after high-impact changes.