Skip to main content

Roles & Permissions

Role-based access control for ATLAS. Each role maps to specific scopes that gate API and UI operations.

Role Definitions

Administrator

admin

Full access to all capabilities, teams, runtime, and admin functions.

capability:readcapability:writecapability:manageteam:readteam:writeteam:manageruntime:planadmin:*

Editor

editor

Can create and edit capabilities and teams. Cannot delete or manage admin settings.

capability:readcapability:writeteam:readteam:writeruntime:plan

Viewer

viewer

Read-only access to the catalog, teams, and governance dashboards.

capability:readteam:read

Team Lead

team_lead

Can manage their own team and its capabilities. Cannot modify other teams.

capability:readcapability:writeteam:readteam:writeteam:manage

Scope Reference

ScopeOperationsRoles
capability:readGET /v1/capabilities, /v1/catalogall
capability:writePOST, PATCH /v1/capabilitiesadmin, editor, team_lead
capability:manageDELETE /v1/capabilitiesadmin
team:readGET /v1/teamsall
team:writePOST, PATCH /v1/teamsadmin, editor, team_lead
team:manageDELETE /v1/teamsadmin, team_lead
runtime:planPOST /v1/runtime/*, health probes, gateway statusadmin, editor
admin:*POST /admin/seed, /admin/migrate, settingsadmin

Registered Principals (0)

ATLAS — Capability & Context Control Plane