Create scoped access grants
Choose actions, resource scope, limits, and expiry for a member instead of granting broad access.
Before you begin
Open People and scroll to Access Control. This area requires the team-collaboration plan feature. Owners and admins manage grants and approve requests. Members can review their own grants and submit requests.
Organization roles and agent action grants are separate. Elevated owners and admins have full agent access; a deny grant is not a way to restrict an organization admin.
Create a grant for a member
- Select the member's access card and open Create Grant.
- Set Target to the intended server. All servers creates an organization-wide grant.
- Choose Effect: allow or deny.
- Select the needed Actions. An unchecked action is outside this grant.
- Choose Scope kind and its resource matchers.
- Set applicable limits and an expiry when the access is temporary.
- Add a Reason, then choose Add Grant.
A target chooses where the grant applies. Its scope chooses what resources it matches. Its actions choose which operations it permits or denies. Check all three before saving.
Keep a grant narrow
| Scope | Examples of what it restricts |
|---|---|
| File | Paths, path-match mode, and applicable file limits |
| Command | Command matchers and allowed operations |
| Server information | Specific information fields |
| Database | Sources and relevant database operations |
| Docker or Podman | Matching containers or resources and allowed actions |
| Kubernetes | Matching cluster resources and operations |
| Player or player-admin | Matching players and player operations |
| Process, service, or user | Matching host resources |
Select a matcher appropriate to the resource. Do not use an unrestricted scope when the member only needs to read a specific directory or inspect one workload.
For members, a matching active deny takes priority over a matching allow. Expired grants do not authorize new operations. An allow does not override the host filesystem or cluster RBAC.
Request access as a member
Use Request Grant, choose the scope and actions you need, and select Submit Request. Check Your Requests for the result.
Owners and admins review Pending Requests and approve or deny them. After approval, reopen the affected panel and test a small read before taking a write action.
Review and revoke
Inspect the member's current grants, including their target, effect, reason, and expiry. Revoke obsolete grants. Check organization-wide grants as well as server-specific grants when access is broader than expected.
Next: access model and missing-panel troubleshooting.
Was this page helpful?
Send a quick note if anything is missing or unclear.
Last updated on