k0rdent AI Docs
WIP

RBAC

Role-based access control for Arc

Atlas RBAC (Role-based access control)

Atlas is the provider console for infrastructure operators. It operates in a platform-scoped context—no customer organization isolation.

Atlas Roles

RoleDescriptionCapabilities
super_adminFull platform controlAll operations, system config, all impersonation
provider_adminOrganization managementCreate/manage customer orgs, impersonate users, modify settings
provider_operatorInfrastructure operationsProvision servers, manage resources, no impersonation
provider_revenueBusiness & revenue operationsView all data, analytics, billing, pricing, audit logs (read-only)
supportCustomer supportRead-only access, impersonate for troubleshooting (read-only)

Role Permissions Matrix

Permissionsuper_adminprovider_adminprovider_operatorprovider_revenuesupport
View all resources
View all orgs/projects
View analytics
View audit logs
View billing/revenue
Manage pricing
Export reports
Manage servers
Power/lifecycle
Create/manage orgs
Modify org settings
Impersonate (full)
Impersonate (read-only)
System configuration
Manage Atlas users

Arc RBAC (Role-based access control)

Arc is the customer self-service portal. It uses an organization plugin for multi-tenancy.

Organization Roles

RoleScopeDescription
ownerAll projectsFull org control, settings, billing, member management
adminAll projectsCreate/manage resources, deployments, kubeconfig access
memberAssigned projectsAccess assigned projects, view org-wide projects

Organization Roles Permissions Matrix

Permissionowneradminmember
View all resources
View all orgs/projects
View analytics
View audit logs
View billing/revenue
Manage pricing
Export reports
Manage resources
Power/lifecycle
Create/manage projects
Modify org settings
System configuration
Manage Arc users

Project Roles

RoleDescription
adminFull project control, manage members, change visibility
memberDeploy and manage resources within project

Project Roles Permissions Matrix

Permissionadminmember
View all resources
View all orgs/projects
View analytics
View audit logs
View billing/revenue
Manage pricing
Export reports
Manage servers
Power/lifecycle
Modify project settings
Manage project members

Project Visibility

ValueBehavior
orgAll org members can view (read-only access)
members_onlyOnly project members + org owner/admin can view and access

Last updated on

How is this guide?

On this page