Roles and permissions
Organization roles in SBOM Observer and the permissions each one grants.
Each member of an organization has one top-level role: owner, admin, member, or viewer. Billing is an add-on role that can be given in addition to a top-level role. Permissions apply to every namespace in the organization. For how roles relate to sign-in, see Authentication and access control.
Roles
| Role | Type | Namespaces | Billing | Organization |
|---|---|---|---|---|
| Owner | top-level | create, update, delete, read, write | read, update | manage members and invitations, delete the organization |
| Admin | top-level | create, update, delete, read, write | none | manage members and invitations |
| Member | top-level | read, write | none | none |
| Viewer | top-level | read | none | none |
| Billing | add-on | none (from the top-level role) | read | none |
Namespace read covers everything inside a namespace: attestations, components, vulnerabilities, policies, and violations. Write covers changing that content: uploading SBOMs, editing policies, annotations, and projects. Namespace create, update, delete apply to the namespace itself.
Access tokens used by the CLI and API are checked separately by the namespace they were created in. See Access tokens.
Related
- Concept: Authentication and access control