Skip to content

Roles & Permissions

How to use built-in or custom roles to control access.

Note: Organization roles control what you and your service accounts can do. Teams describe operational ownership and notification routing. These are separate controls.

Role Purpose
Owner Full organization administration and lockout recovery
Security Admin Security operations without ownership transfer
Team Member Product read baseline
Policy Automation Service-account preset for draft mapping updates

Note: The Policy Automation role is intended for service accounts and API keys. It does not include policy publication.

Permissions combine a resource, such as repository or policy_group, with an action, such as read, write, manage, or policy_publish.

When a member has more than one role, BIMP combines the valid permissions from those roles.

Use the permission matrix under Settings → Organization → Roles and permissions as the current source for available permissions.

Open Settings → Organization → Membership, find the member, and select the appropriate roles.

Before removing an Owner role, confirm that another active Owner can recover organization access.

Under Roles and permissions:

  1. choose Create role;
  2. enter a clear label and key;
  3. select the minimum permissions needed; and
  4. save the role before assigning it to members or service accounts.

You can use a built-in role as a starting point for customization.

Review current assignments before deleting or changing a role. You can review role assignments in Settings → Organization → Membership.

Before deletion, move members and service accounts to another appropriate role.

When creating an API key, choose either:

  • a built-in or custom role; or
  • an explicit set of permissions.

Prefer the narrowest access that can complete the automation. An API key remains bound to its organization and cannot use another organization ID to cross that boundary.

If an action returns 403, confirm the active organization and the identity’s current roles. Ask an Owner to restore the specific missing authority.