Manage members and roles
Invite, remove, change roles. Define custom roles when the built-ins don't fit.
Invite a member
Sidebar → Organizations → your org → Members tab → Invite Member.
- Email — invitee's address
- Role — built-in or custom (see below)
- Expires in — invitation token validity (default 7 days)
Send. DT Edge Platform emails the invitee a one-time link. Pending invitations show in the same Members tab, in their own row block.
Change a member's role
Members tab → row actions → Change role → pick a new role → save. Effective immediately on their next request; their open sessions don't need to re-login.
Remove a member
Members tab → row actions → Remove. Confirms with a dialog.
The member's user account stays alive; only this org's membership
- casbin role grant go away. They lose access to org-scoped pages on their next request.
Cancel a pending invitation
Same Members tab → in the Pending block → row actions → Cancel. The invitation token is invalidated; clicking the link in the email afterwards goes to a "this invitation is no longer valid" page.
Built-in roles
Your install ships with these (subject to admin customisation in Admin → Settings → Roles defaults):
- admin — full org access including members + roles + delete
- developer — install / upgrade / uninstall; manage registries and marketplace; view alarms
- operator — developer + manage alarms + view all org data
- viewer — read-only
What each can actually do is governed by permissions, not role names. See Reference: permissions for the exact list.
Define a custom role
Sidebar → Organizations → your org → Roles tab → Add role.
- Name — displayed everywhere members are managed
- Description — tooltip / help text
- Permissions — multi-select grid grouped by resource
(
edge-instances:*,helm:*,marketplace:*, etc.)
Save. The role becomes available in the Members tab role picker.
You can edit a custom role afterwards; changes propagate to every member assigned to it on their next request. You can't edit built-in roles, but you can copy one as a starting point for a custom one.
Delete a custom role
Roles tab → row actions → Delete.
Refuses if any member is currently assigned this role — change those members to another role first.
Tips
- Default people to
viewerif you're unsure. Promote later when they need more. - For automation (CI / scripts), don't share a teammate's account — create a dedicated user with a focused role and give the script that user's API key. See Reference: API keys.
- Role changes are recorded in the audit log; you can answer "who promoted X to admin" from Audit Logs.
Common errors
permission denied— you're trying to manage members withoutmembers:create/members:update/members:deletenot a member of this organization— you got logged out of the org; switch back via the selectorAPI_KEY_NOT_FOUND— different feature; see How-to: manage API keys (different surface)
SSO and roles
If this org has SSO enabled (Organizations → <org> → SSO),
roles can be driven by IdP groups instead of (or alongside)
manual assignment.
Per-org group → role mapping
In the SSO tab, the Group → role mapping section lets you write rows like:
acme-admins → admin
acme-engineers → editor
acme-readonly → viewer
On every SSO login dtedge reconciles the user's roles in this org: adds the roles for groups they're in, removes the roles for groups they're no longer in.
What stays manual
- Roles outside the mapping universe stay safe. If you manually granted "admin" to someone whose IdP group only maps to "editor", the manual admin role stays — reconcile only touches roles the mapping references.
- The default role (set when auto-provision is on) is granted on first login regardless of mapping.
When IdP groups disappear
If the IdP stops shipping the groups claim entirely (broken
Action, removed scope), dtedge skips reconcile rather than
revoking everything. Without that safety net every user would
lose every mapping-driven role on every login.
For full setup walkthroughs see Admin → Configure per-org SSO.