Skip to content

People and roles

Everyone in a workspace has a role. A role is a set of permissions that you define once and apply to many people.

Each new workspace starts with four roles. Choose one to see what it allows.

Choose a role

Day-to-day operations without root. New invitations use this role by default.

Observe

  • View device detailsIdentity, connection and last reported system information.device.readAllowed
  • View servicesSee the services a device reports.services.readAllowed
  • Read metricsSystem and process measurements.metrics.readAllowed
  • Read logsCollected service logs.logs.readAllowed
  • Read activity and recordingsSubmitted commands, outcomes and full terminal recordings.audit.readAllowed

Operate

  • Restart servicesRestart a service without general sudo.services.restartAllowed
  • Change monitoring settingsTurn collection on and choose services.monitoring.writeAllowed
  • Edit device detailsRename devices and change tags.device.writeAllowed
  • Update the Suta agentInstall a published agent release.agent.updateAllowed
  • Configure networkingApprove local network repair.network.writeNot allowed

Connect & administer

  • Manage remote accessOpen, change or close a remote access window.access.writeAllowed
  • Run commandsRun commands and terminals without sudo.commands.execAllowed
  • Run commands with sudoFull administration of the device.commands.sudoNot allowed
  • Enroll devicesAdd new devices to the workspace.device.enrollNot allowed
  • Remove devicesRemove devices and revoke their access.device.removeNot allowed

Admin is protected: you can’t edit or delete it, and a workspace always keeps at least one admin. You can edit the other three and create your own.

You need to be an admin.

  1. Go to Settings > People and select Invite someone.

  2. Enter their Email address and choose a Role.

  3. Select Send invite.

The person receives an email. They must accept it within seven days, signed in with that email address. To cancel an invitation, find it under Pending invitations and select Revoke.

Change someone’s role from the picker next to their name in People, or open them and select Remove from workspace. The change takes effect immediately and closes any terminal sessions they have open.

  1. Go to Settings > Roles and select Create role, or Edit on an existing role.

  2. Start from a preset, name the role and choose its permissions.

  3. To make it the default for new invitations, select Use for new invitations.

  4. Select Create role or Save role for everyone.

Editing a role changes access for everyone who has it, straight away. You can’t delete a role that’s in use or is the default.