Owner
Full control over the organization. Can manage all settings, users, projects, and resources.
Highest privilegeUnderstand the built-in roles, how access works in AXIO, and the core principles that keep your organization secure and simple.
AXIO uses a role-based access model with scope-based access to ensure users can only see and perform actions that are relevant to their role and scope.
Full control over the organization. Can manage all settings, users, projects, and resources.
Highest privilegeManages users, roles, projects, and platform settings within their assigned scope.
High privilegeCan create and manage resources (e.g., stacks) and operate within their assigned scope.
Standard accessRead-only access. Can view resources and data within their assigned scope.
Read-only accessNo access to any resources. Access is granted only after a role is assigned.
No accessDefines what a user can do (permissions). Example: Member can create stacks, Viewer can only view.
Defines where a user can access. Hierarchy: Organization → Project → Workspace → Environment.
The most-specific role in the hierarchy (e.g., Environment) always takes precedence.
A collection of users who can be assigned roles together to simplify management.
A user or group is assigned a role.
The role is assigned at a specific scope (Org / Project / Workspace / Environment).
The user can access resources based on their role and scope.
The same rules are enforced in the UI, API, and all platform operations.
Built-in roles (Owner, Admin, Member, Viewer) decide WHERE a user can go (scope).
Custom roles decide WHAT EXTRA they can do, but they never open new scope.
This guide uses simple language to help everyone understand roles and access clearly.