Skip to main content
The Console uses workspace roles to separate administration, operations, billing, and read access. Roles are fixed capability sets defined by Acrity: you assign a role to each member, and that role determines exactly what they can do.

Main roles

Permission matrix

The Repositories, Credentials, and Connected Apps screens require a Workspace admin (platform admins also have access). Maintainers do not manage these screens; they act on reviews through pull and merge requests and the API.

Best practices

  • Keep at least two workspace admins per workspace.
  • Assign the Billing Manager role to people who need billing access but should not manage credentials or other technical settings.
  • Remove users who left the team and revoke pending invites.
  • Review API keys and webhooks whenever workspace admins change.

Where to manage

Everyone can view the workspace member list. Only a Workspace admin can invite members or change roles.
Do not share accounts between people. For auditability and security, each user should access the Console with their own identity.