Skip to main content

Manage members and roles

Invite, remove, change roles. Define custom roles when the built-ins don't fit.

Invite a member​

Sidebar → Organizations → your org → Members tab → Invite Member.

  • Email — invitee's address
  • Role — built-in or custom (see below)
  • Expires in — invitation token validity (default 7 days)

Send. DT Edge Platform emails the invitee a one-time link. Pending invitations show in the same Members tab, in their own row block.

Change a member's role​

Members tab → row actions → Change role → pick a new role → save. Effective immediately on their next request; their open sessions don't need to re-login.

Remove a member​

Members tab → row actions → Remove. Confirms with a dialog.

The member's user account stays alive; only this org's membership

  • casbin role grant go away. They lose access to org-scoped pages on their next request.

Cancel a pending invitation​

Same Members tab → in the Pending block → row actions → Cancel. The invitation token is invalidated; clicking the link in the email afterwards goes to a "this invitation is no longer valid" page.

Built-in roles​

Your install ships with these (subject to admin customisation in Admin → Settings → Roles defaults):

  • admin — full org access including members + roles + delete
  • developer — install / upgrade / uninstall; manage registries and marketplace; view alarms
  • operator — developer + manage alarms + view all org data
  • viewer — read-only

What each can actually do is governed by permissions, not role names. See Reference: permissions for the exact list.

Define a custom role​

Sidebar → Organizations → your org → Roles tab → Add role.

  • Name — displayed everywhere members are managed
  • Description — tooltip / help text
  • Permissions — multi-select grid grouped by resource (edge-instances:*, helm:*, marketplace:*, etc.)

Save. The role becomes available in the Members tab role picker.

You can edit a custom role afterwards; changes propagate to every member assigned to it on their next request. You can't edit built-in roles, but you can copy one as a starting point for a custom one.

Delete a custom role​

Roles tab → row actions → Delete.

Refuses if any member is currently assigned this role — change those members to another role first.

Tips​

  • Default people to viewer if you're unsure. Promote later when they need more.
  • For automation (CI / scripts), don't share a teammate's account — create a dedicated user with a focused role and give the script that user's API key. See Reference: API keys.
  • Role changes are recorded in the audit log; you can answer "who promoted X to admin" from Audit Logs.

Common errors​

  • permission denied — you're trying to manage members without members:create / members:update / members:delete
  • not a member of this organization — you got logged out of the org; switch back via the selector
  • API_KEY_NOT_FOUND — different feature; see How-to: manage API keys (different surface)

SSO and roles​

If this org has SSO enabled (Organizations → <org> → SSO), roles can be driven by IdP groups instead of (or alongside) manual assignment.

Per-org group → role mapping​

In the SSO tab, the Group → role mapping section lets you write rows like:

acme-admins → admin
acme-engineers → editor
acme-readonly → viewer

On every SSO login dtedge reconciles the user's roles in this org: adds the roles for groups they're in, removes the roles for groups they're no longer in.

What stays manual​

  • Roles outside the mapping universe stay safe. If you manually granted "admin" to someone whose IdP group only maps to "editor", the manual admin role stays — reconcile only touches roles the mapping references.
  • The default role (set when auto-provision is on) is granted on first login regardless of mapping.

When IdP groups disappear​

If the IdP stops shipping the groups claim entirely (broken Action, removed scope), dtedge skips reconcile rather than revoking everything. Without that safety net every user would lose every mapping-driven role on every login.

For full setup walkthroughs see Admin → Configure per-org SSO.

See also​