Built-in roles
Opper has four built-in roles. Each role includes everything the role before it can do.What each role can do
Workspace
Run models and routes covers calls made with the member’s API keys and
calls made in the playground.
Configure dynamic routes covers everything that changes a
dynamic route: creating, editing, deploying,
rolling back and deleting it.
Observability & governance
A member with View trace metadata but without View trace inputs and
outputs can open Traces and Logs,
but does not see prompts, responses or other captured content.
Organization
Management credentials are the management keys used with the
Management API.
View billing decides whether the organization’s balance, spend and budget
are included when one of the member’s API keys calls
GET /v3/me. In the
platform, every member can open Settings, then Billing & Credits, and
see the balance, spend and recent activity. Only a role with Manage billing
and plans can add credit, change auto-recharge or change the plan.Who can view and change rules
- View rules: Owner, Admin and Developer. Viewer cannot view rules.
- Change rules: Owner and Admin. Developer and Viewer cannot change rules.
- Does not see the Rules link under Observe & Control in the sidebar.
- Sees a panel titled Rules are managed by your administrators in place of the Rules page, and in place of the Effective policy section on the dashboard.
Which plans can choose roles
Custom roles
Custom roles are available on the Enterprise plan only. A custom role can hold any subset of the permissions an Admin holds. It can never hold the two Owner-only permissions: Transfer ownership and Delete the organization. Use a custom role when a built-in role holds more than you want a member to have. For example, a custom role can run models without being able to configure dynamic routes. To create one, your role must hold Create and edit roles. Open Settings, then Roles & permissions, and select Create role. Enter a Role name, select the permissions the role should hold, and select Save role. You can only grant permissions that your own role holds. The role editor uses the group, resource and permission names from the tables above. It lists every permission in those tables except Set up and enforce single sign-on and the two Owner-only permissions. A custom role is assigned the same way as a built-in role: in the invite dialog, or in the role dropdown on the Users page.The Owner
- The person who creates an organization is its Owner.
- An organization has one Owner.
- Owner cannot be chosen in an invitation or in the role dropdown. It moves only when the current Owner transfers ownership.
- The Owner cannot leave the organization or be removed from it. Transfer ownership first.
Transfer ownership
Only the Owner can transfer ownership, and only to someone who is already a member of the organization.- Open Settings, then Users.
- In the row of the member who should become the Owner, open the actions menu and select Make owner.
- Select Make owner again to confirm.
Invite a member with a role
To invite members, your role must hold Manage members and assign roles (Owner and Admin do).- Open Settings, then Users.
- Select Invite user.
- Enter one email address in each row.
- On Control Plane and Enterprise, choose a role in the Role column of each row. You can only choose roles whose permissions your own role also holds. On all other plans the Role column is locked to Admin.
- Check the role shown next to each email address.
- Select Send invitations.
Change a role
Changing a member’s role requires the Control Plane or Enterprise plan, and a role that holds Manage members and assign roles (Owner and Admin do).- Open Settings, then Users.
- In the member’s row, open the role dropdown.
- Select the new role.
- The member is the Owner. Use Transfer ownership instead.
- The member’s role is managed by your identity provider through single sign-on. The label shows SSO next to the role.
- The member’s current role holds a permission that your own role does not hold.
- Your organization’s plan does not include role choice, or your own role does not hold Manage members and assign roles.
Permission identifier reference
This section is a reference for Enterprise organizations that use custom roles. It lists the identifier of each permission in the tables above.
A custom role that holds Manage billing and plans can also view billing.
Management API keys have their own list of
scopes. Some scopes share a
name with a permission above, but a scope limits what a key can do and a
permission limits what a member can do.