People and roles
Everyone in a workspace has a role. A role is a set of permissions that you define once and apply to many people.
Built-in roles
Section titled “Built-in roles”Each new workspace starts with four roles. Choose one to see what it allows.
Day-to-day operations without root. New invitations use this role by default.
Observe
- View device detailsIdentity, connection and last reported system information.
device.readAllowed - View servicesSee the services a device reports.
services.readAllowed - Read metricsSystem and process measurements.
metrics.readAllowed - Read logsCollected service logs.
logs.readAllowed - Read activity and recordingsSubmitted commands, outcomes and full terminal recordings.
audit.readAllowed
Operate
- Restart servicesRestart a service without general sudo.
services.restartAllowed - Change monitoring settingsTurn collection on and choose services.
monitoring.writeAllowed - Edit device detailsRename devices and change tags.
device.writeAllowed - Update the Suta agentInstall a published agent release.
agent.updateAllowed - Configure networkingApprove local network repair.
network.writeNot allowed
Connect & administer
- Manage remote accessOpen, change or close a remote access window.
access.writeAllowed - Run commandsRun commands and terminals without sudo.
commands.execAllowed - Run commands with sudoFull administration of the device.
commands.sudoNot allowed - Enroll devicesAdd new devices to the workspace.
device.enrollNot allowed - Remove devicesRemove devices and revoke their access.
device.removeNot allowed
Admin is protected: you can’t edit or delete it, and a workspace always keeps at least one admin. You can edit the other three and create your own.
Invite someone
Section titled “Invite someone”You need to be an admin.
-
Go to Settings > People and select Invite someone.
-
Enter their Email address and choose a Role.
-
Select Send invite.
The person receives an email. They must accept it within seven days, signed in with that email address. To cancel an invitation, find it under Pending invitations and select Revoke.
Change or remove someone
Section titled “Change or remove someone”Change someone’s role from the picker next to their name in People, or open them and select Remove from workspace. The change takes effect immediately and closes any terminal sessions they have open.
Create or edit a role
Section titled “Create or edit a role”-
Go to Settings > Roles and select Create role, or Edit on an existing role.
-
Start from a preset, name the role and choose its permissions.
-
To make it the default for new invitations, select Use for new invitations.
-
Select Create role or Save role for everyone.
Editing a role changes access for everyone who has it, straight away. You can’t delete a role that’s in use or is the default.