EnderDash

Create scoped access grants

Choose actions, resource scope, limits, and expiry for a member instead of granting broad access.

Before you begin

Open People and scroll to Access Control. This area requires the team-collaboration plan feature. Owners and admins manage grants and approve requests. Members can review their own grants and submit requests.

Organization roles and agent action grants are separate. Elevated owners and admins have full agent access; a deny grant is not a way to restrict an organization admin.

Create a grant for a member

  1. Select the member's access card and open Create Grant.
  2. Set Target to the intended server. All servers creates an organization-wide grant.
  3. Choose Effect: allow or deny.
  4. Select the needed Actions. An unchecked action is outside this grant.
  5. Choose Scope kind and its resource matchers.
  6. Set applicable limits and an expiry when the access is temporary.
  7. Add a Reason, then choose Add Grant.

A target chooses where the grant applies. Its scope chooses what resources it matches. Its actions choose which operations it permits or denies. Check all three before saving.

Keep a grant narrow

ScopeExamples of what it restricts
FilePaths, path-match mode, and applicable file limits
CommandCommand matchers and allowed operations
Server informationSpecific information fields
DatabaseSources and relevant database operations
Docker or PodmanMatching containers or resources and allowed actions
KubernetesMatching cluster resources and operations
Player or player-adminMatching players and player operations
Process, service, or userMatching host resources

Select a matcher appropriate to the resource. Do not use an unrestricted scope when the member only needs to read a specific directory or inspect one workload.

For members, a matching active deny takes priority over a matching allow. Expired grants do not authorize new operations. An allow does not override the host filesystem or cluster RBAC.

Request access as a member

Use Request Grant, choose the scope and actions you need, and select Submit Request. Check Your Requests for the result.

Owners and admins review Pending Requests and approve or deny them. After approval, reopen the affected panel and test a small read before taking a write action.

Review and revoke

Inspect the member's current grants, including their target, effect, reason, and expiry. Revoke obsolete grants. Check organization-wide grants as well as server-specific grants when access is broader than expected.

Next: access model and missing-panel troubleshooting.

Was this page helpful?

Send a quick note if anything is missing or unclear.

Last updated on

On this page