Roles & Access Overview

Understand the built-in roles, how access works in AXIO, and the core principles that keep your organization secure and simple.

i

AXIO uses a role-based access model with scope-based access to ensure users can only see and perform actions that are relevant to their role and scope.

Owner

Full control over the organization. Can manage all settings, users, projects, and resources.

Highest privilege

Admin

Manages users, roles, projects, and platform settings within their assigned scope.

High privilege

Member

Can create and manage resources (e.g., stacks) and operate within their assigned scope.

Standard access

Viewer

Read-only access. Can view resources and data within their assigned scope.

Read-only access

Unassigned

No access to any resources. Access is granted only after a role is assigned.

No access

2 Key Concepts

Role

Defines what a user can do (permissions). Example: Member can create stacks, Viewer can only view.

Scope

Defines where a user can access. Hierarchy: Organization → Project → Workspace → Environment.

Most-Specific Role

The most-specific role in the hierarchy (e.g., Environment) always takes precedence.

Group

A collection of users who can be assigned roles together to simplify management.

3 How Access Works

♟+

1. Assign Role

A user or group is assigned a role.

2. Define Scope

The role is assigned at a specific scope (Org / Project / Workspace / Environment).

3. Access Granted

The user can access resources based on their role and scope.

4. Enforced Everywhere

The same rules are enforced in the UI, API, and all platform operations.

💡

Core Principle

Built-in roles (Owner, Admin, Member, Viewer) decide WHERE a user can go (scope).
Custom roles decide WHAT EXTRA they can do, but they never open new scope.

i

This guide uses simple language to help everyone understand roles and access clearly.