Skip to content

Commit ba46eaa

Browse files
committed
Rewritten
Signed-off-by: Lee Calcote <lee.calcote@layer5.io>
1 parent d960219 commit ba46eaa

File tree

1 file changed

+27
-6
lines changed

1 file changed

+27
-6
lines changed

content/en/cloud/security/roles.md

Lines changed: 27 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,12 @@
11
---
22
title: Roles
33
description: >
4-
A role contains a set of permissions that allows you to perform specific actions on Layer5 Cloud resources. To make permissions available to principals, including users, you grant roles to the principals.
4+
Roles map permissions to users. Roles contain any number of keychains, which contain any number of keys (permissions). Assign roles to users to grant permissions.
55
date: 2023-10-30
66
categories: [Security]
77
tags: [roles, permissions]
88
---
9+
Roles map permissions to users. Roles contain any number of keychains, which contain any number of keys (permissions). Assign roles to users to grant permissions.
910

1011
## Provider Admin Role
1112

@@ -44,19 +45,24 @@ tags: [roles, permissions]
4445
{{% card header="Organization Adminstrator" %}}
4546

4647
**What is the purpose of this role?**
48+
4749
- Administration of an organization
4850

4951
**Who can assign this role?**
52+
5053
- The Organization Owner
5154

5255
**When this role first assigned?**
56+
5357
- Creation of new organization or User Account creation
5458

5559
**How many instances of these roles?**
60+
5661
- Min: 1, Max: many (based on plan)
5762
- By default, the first Organization Admin is the owner (the creator of the organization).
5863

5964
**Who can remove assignment of this role?**
65+
6066
- Organization Owner
6167

6268
{{% /card %}}
@@ -86,8 +92,12 @@ tags: [roles, permissions]
8692
{{< /cardpane >}}
8793

8894
{{< alert title="Organization owners as entitlements" >}}
89-
It's essential to understand that organization owners are not roles but entitlements. These entitlements are automatically assigned to the user who creates an organization. They are granted certain administrative privileges within the organization, allowing them to manage its settings and members effectively, including the administrative privilege to delete the organization.
90-
<br><br>
95+
It's essential to understand that owners are not roles, but entitlements.
96+
97+
Organization owners carry the organization administrator role, and may be joined in their organization administration duties by any number of other users carrying the organization administrator role. However, the organization owner also has the administrative privilege to delete the organization.
98+
99+
The entitlement of "organization owner" is automatically bestowed to the creator of a organization. The individual user who created a given organization initially is therefore granted certain administrative privileges beyond that of other organization administrators. Specifically, organization owners retain the sole permission to delete the organization.
100+
91101
For more information, see [Organization](/cloud/identity/organizations).
92102
{{< /alert >}}
93103

@@ -96,12 +106,15 @@ For more information, see [Organization](/cloud/identity/organizations).
96106
{{< cardpane >}}
97107
{{% card header="Team Adminstrator" %}}
98108
**What is the purpose of this role?**
109+
99110
- Administration of teams
100111

101112
**Who can assign and unassign this role?**
113+
102114
- Organization Administrator or Team owner
103115

104116
**When this role first assigned?**
117+
105118
- Creation of new team or User Account creation
106119
- By default, the first Team Admin is owner (the team creator)
107120

@@ -111,22 +124,30 @@ Min: 1, Max: many
111124
{{% /card %}}
112125
{{% card header="Team Manager" %}}
113126
**What is the purpose of this role?**
127+
114128
- Administration of teams (without delete access)
115129

116130
**Who can assign and unassign this role?**
131+
117132
- Organization Administrators or Team Owner
118133

119134
**When this role first assigned?**
135+
120136
- Manually by Organization Administrator or Team Owner
121137

122138
**How many instances of these roles?**
139+
123140
- Min: 0, Max: many
124141
{{% /card %}}
125142
{{< /cardpane >}}
126143

127-
{{< alert title="Team owners as entitlements" >}}
128-
It's essential to understand that team owners are not roles but entitlements. These entitlements are automatically assigned to the user who creates an team within an organization. They are granted certain administrative privileges within the team, allowing them to manage its settings and members effectively, including the administrative privilege to delete the team.
129-
<br><br>
144+
{{< alert title="Owners as entitlements, not roles" >}}
145+
It's essential to understand that owners are not roles, but entitlements.
146+
147+
Team owners carry the team administrator role, and may be joined in their team administration duties by any number of other users carrying the team administrator role. However, the team owner also has the administrative privilege to delete the team.
148+
149+
The entitlement of "team owner" is automatically bestowed to the creator of a team. The individual user who created a given team initially is therefore granted certain administrative privileges beyond that of other team administrators. Specifically, team owners retain the sole permission to delete the team.
150+
130151
For more information, see [Teams](/cloud/identity/teams).
131152
{{< /alert >}}
132153

0 commit comments

Comments
 (0)