[{"data":1,"prerenderedAt":248},["ShallowReactive",2],{"content-query-nDxmB0xWdK":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"sidebar_position":10,"body":11,"_type":242,"_id":243,"_source":244,"_file":245,"_stem":246,"_extension":247},"\u002Fdocs\u002Ffeatures\u002Fteams-rbac","features",false,"","RBAC & Team Management","CredVault supports deep multi-tenant organization structures, allowing you to invite team members to collaborate on workspaces with highly granular Role-Based Access Control (RBAC).",5,{"type":12,"children":13,"toc":232},"root",[14,22,27,34,39,45,50,168,174,181,186,192,197],{"type":15,"tag":16,"props":17,"children":19},"element","h1",{"id":18},"rbac-team-management",[20],{"type":21,"value":8},"text",{"type":15,"tag":23,"props":24,"children":25},"p",{},[26],{"type":21,"value":9},{"type":15,"tag":28,"props":29,"children":31},"h2",{"id":30},"workspaces",[32],{"type":21,"value":33},"Workspaces",{"type":15,"tag":23,"props":35,"children":36},{},[37],{"type":21,"value":38},"A Workspace is an isolated environment containing Clusters, Functions, and API Keys. Users can belong to multiple workspaces simultaneously, seamlessly switching between them from the top-left corner of the Dashboard.",{"type":15,"tag":28,"props":40,"children":42},{"id":41},"roles-permissions",[43],{"type":21,"value":44},"Roles & Permissions",{"type":15,"tag":23,"props":46,"children":47},{},[48],{"type":21,"value":49},"When inviting a user to a Workspace, you assign them a strict Role that dictates exactly what they can do:",{"type":15,"tag":51,"props":52,"children":53},"table",{},[54,78],{"type":15,"tag":55,"props":56,"children":57},"thead",{},[58],{"type":15,"tag":59,"props":60,"children":61},"tr",{},[62,68,73],{"type":15,"tag":63,"props":64,"children":65},"th",{},[66],{"type":21,"value":67},"Role",{"type":15,"tag":63,"props":69,"children":70},{},[71],{"type":21,"value":72},"Capabilities",{"type":15,"tag":63,"props":74,"children":75},{},[76],{"type":21,"value":77},"Ideal For",{"type":15,"tag":79,"props":80,"children":81},"tbody",{},[82,105,126,147],{"type":15,"tag":59,"props":83,"children":84},{},[85,95,100],{"type":15,"tag":86,"props":87,"children":88},"td",{},[89],{"type":15,"tag":90,"props":91,"children":92},"strong",{},[93],{"type":21,"value":94},"Owner",{"type":15,"tag":86,"props":96,"children":97},{},[98],{"type":21,"value":99},"Absolute control. Can delete workspaces, change billing, and manage all users.",{"type":15,"tag":86,"props":101,"children":102},{},[103],{"type":21,"value":104},"Founders, CTOs",{"type":15,"tag":59,"props":106,"children":107},{},[108,116,121],{"type":15,"tag":86,"props":109,"children":110},{},[111],{"type":15,"tag":90,"props":112,"children":113},{},[114],{"type":21,"value":115},"Admin",{"type":15,"tag":86,"props":117,"children":118},{},[119],{"type":21,"value":120},"Can create\u002Fdelete clusters, manage API keys, and invite other Members. Cannot alter billing.",{"type":15,"tag":86,"props":122,"children":123},{},[124],{"type":21,"value":125},"Engineering Managers",{"type":15,"tag":59,"props":127,"children":128},{},[129,137,142],{"type":15,"tag":86,"props":130,"children":131},{},[132],{"type":15,"tag":90,"props":133,"children":134},{},[135],{"type":21,"value":136},"Developer",{"type":15,"tag":86,"props":138,"children":139},{},[140],{"type":21,"value":141},"Can read\u002Fwrite to databases, deploy functions, and view logs. Cannot manage settings.",{"type":15,"tag":86,"props":143,"children":144},{},[145],{"type":21,"value":146},"Software Engineers",{"type":15,"tag":59,"props":148,"children":149},{},[150,158,163],{"type":15,"tag":86,"props":151,"children":152},{},[153],{"type":15,"tag":90,"props":154,"children":155},{},[156],{"type":21,"value":157},"Viewer",{"type":15,"tag":86,"props":159,"children":160},{},[161],{"type":21,"value":162},"Read-only access to logs, metrics, and data querying. Cannot mutate any state.",{"type":15,"tag":86,"props":164,"children":165},{},[166],{"type":21,"value":167},"Data Analysts, PMs",{"type":15,"tag":28,"props":169,"children":171},{"id":170},"managing-team-members",[172],{"type":21,"value":173},"Managing Team Members",{"type":15,"tag":175,"props":176,"children":178},"h3",{"id":177},"inviting-members",[179],{"type":21,"value":180},"Inviting Members",{"type":15,"tag":23,"props":182,"children":183},{},[184],{"type":21,"value":185},"From the Settings -> Members page, you can invite colleagues via email. They will receive a secure, one-time invitation link to join your Workspace.",{"type":15,"tag":175,"props":187,"children":189},{"id":188},"enforcing-policies",[190],{"type":21,"value":191},"Enforcing Policies",{"type":15,"tag":23,"props":193,"children":194},{},[195],{"type":21,"value":196},"Enterprise administrators can enforce organization-wide policies on all workspace members:",{"type":15,"tag":198,"props":199,"children":200},"ul",{},[201,212,222],{"type":15,"tag":202,"props":203,"children":204},"li",{},[205,210],{"type":15,"tag":90,"props":206,"children":207},{},[208],{"type":21,"value":209},"Required 2FA",{"type":21,"value":211},": Prevent any member from accessing the workspace unless 2FA is enabled on their account.",{"type":15,"tag":202,"props":213,"children":214},{},[215,220],{"type":15,"tag":90,"props":216,"children":217},{},[218],{"type":21,"value":219},"Session Limits",{"type":21,"value":221},": Limit workspace members to a single active session globally to prevent credential sharing.",{"type":15,"tag":202,"props":223,"children":224},{},[225,230],{"type":15,"tag":90,"props":226,"children":227},{},[228],{"type":21,"value":229},"Audit Trails",{"type":21,"value":231},": Every action performed by a team member is logged with their specific User ID to the Activity Log.",{"title":7,"searchDepth":233,"depth":233,"links":234},2,[235,236,237],{"id":30,"depth":233,"text":33},{"id":41,"depth":233,"text":44},{"id":170,"depth":233,"text":173,"children":238},[239,241],{"id":177,"depth":240,"text":180},3,{"id":188,"depth":240,"text":191},"markdown","content:docs:features:teams-rbac.md","content","docs\u002Ffeatures\u002Fteams-rbac.md","docs\u002Ffeatures\u002Fteams-rbac","md",1782233754784]