Skip to content

docs: add Console viewer role to roles and permissions - #2695

Open
olagruchala wants to merge 1 commit into
masterfrom
feat/console-viewer-role
Open

docs: add Console viewer role to roles and permissions#2695
olagruchala wants to merge 1 commit into
masterfrom
feat/console-viewer-role

Conversation

@olagruchala

Copy link
Copy Markdown
Contributor

Documents the read-only Viewer role in the Ory Console for both workspaces and projects.

  • Adds Viewer to the Workspace and Project role sections and to both permission matrices (Viewer / Developer / Owner).
  • Describes what a Viewer can read, and that resource-changing actions (save, create, delete, invite) are disabled with a tooltip.
  • Clarifies that Viewers cannot access runtime data managed by Ory services — identities, sessions, message delivery, OAuth2 clients, permission relationships, and issued & imported API keys.
  • Notes that project roles are additive: a member's effective project role is the higher of their workspace role and any role granted directly on the project. To give a workspace Viewer write access on one
    project, invite them to that project with the Developer role.

Document the read-only Viewer role for workspaces and projects: what it can
read, that resource-changing actions are disabled, and that runtime data —
identities, sessions, message delivery, OAuth2 clients, permission
relationships, and issued and imported API keys — is hidden. Update both
permission matrices, and note that project roles are additive so a member can
hold a higher role on a specific project than their workspace role.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant