ProdgatorDocs
Organization

Roles

The six built-in roles, what each one can do, and how members with several roles work.

Pas encore traduite. Cette page est affichée en anglais. Lire l’original en anglais.

Every member of a Prodgator organization has one or more roles. A member with several roles can do what any of them allows. Roles are sets of permissions, not a ladder: Security and Compliance are separate functions, and neither one includes the other or Developer. Release manager covers what Developer can do, and Org admin holds every permission.

The six roles

RoleWho it is forIn short
ViewerStakeholders, auditors and anyone who only readsReads dashboards, pipelines, deployments, security findings and compliance results. Changes nothing.
DeveloperEngineers who push code and run pipelinesViewer, plus cancel and re-run runs, read failure logs, upload scan reports and re-check pull requests.
Release managerRelease and platform engineers who own gates and deploymentsDeveloper, plus approve and roll back deployments, approve pull requests, override release policies, and manage gates, approver groups and release policies.
SecuritySecurity engineersViewer, plus triage findings, upload scan reports, manage security platform connections and tracked branches, and read failure logs.
ComplianceGovernance, risk and complianceViewer, plus manage compliance policies, run evaluations, answer deployments a Block compliance policy governs, create break-glass overrides and read the audit log.
Org adminOwners and ITEverything, including members, roles, billing, SSO and directory sync, integrations and API keys.

A member can hold several roles, for example Developer and Security. Invitations can carry several roles, and so can directory group mappings: someone in several mapped groups gets every mapped role, not just one of them.

What each role can do

Rows are actions, columns are roles. The table is generated from the same permission list the product uses, so it matches what the product allows.

ActionWhat it coversViewerDeveloperRelease managerSecurityComplianceOrg admin
Pipelines
Cancel runsCancel GitHub Actions, GitLab, Bitbucket and Azure Pipelines runs that are still running.YesYesYes
Re-run runsRe-run failed jobs of finished GitHub Actions, GitLab and Azure Pipelines runs, and re-run one finished GitHub Actions or GitLab job.YesYesYes
Read failure logsRead the logs of failed runs and jobs.YesYesYesYes
Deployments
Approve deploymentsApprove, reject and re-evaluate deployment gates.YesYes
Roll back deploymentsStart a rollback to an earlier deployment.YesYes
Security
Upload security reportsUpload scanner reports and start Wiz or Snyk connector syncs.YesYesYesYes
Triage security findingsDismiss, reopen, split and rejoin alerts, scan results and findings.YesYes
Manage tracked branchesChoose which branches are scanned and tracked for security findings.YesYes
Manage security connectionsConnect and disconnect security scanning platforms.YesYes
Compliance
View enforcementSee enforcement decisions, settings and break-glass overrides.YesYesYesYes
Run compliance evaluationsStart a compliance evaluation.YesYesYes
Manage compliance policiesTurn policies on or off, set enforcement modes and settings, and re-evaluate decisions.YesYes
Answer a deployment that a Block compliance policy governsApprove or reject it with a stated reason.YesYes
Create break-glass overridesSkip a compliance block in an emergency. Each override is recorded.YesYes
Release policies and gates
Inspect policiesOpen the evaluation details and results of a release policy.YesYesYesYesYes
Re-check pull requestsRun the release policies again on a pull request.YesYesYesYesYes
Approve pull requestsApprove a pull request that is waiting on a release policy.YesYes
Override release policiesLet a deployment or pull request through although a release policy failed.YesYes
Edit release policiesCreate, edit, import and bind release policies.YesYes
Edit approver groupsCreate and edit approver groups.YesYes
Edit gatesCreate and edit gates and the deployment environments they link.YesYes
See the member listSee member names and emails, for example to pick approvers.YesYes
Docs, analytics and exports
Generate AI resultsAsk for AI summaries and explanations.YesYesYesYesYes
View SPACE metricsOpen the SPACE developer metrics.YesYes
Share AI widgetsShare AI widgets with the organization and edit shared ones.YesYesYesYes
Export dataStart data exports and download them.YesYesYesYes
Integrations
Work with Jira issuesCreate, link and unlink Jira issues.YesYesYesYesYes
Manage custom adaptersCreate and edit custom adapters and processing rules.YesYes
Audit
Read the audit logOpen the audit log of changes to members, roles and settings.YesYes

Every role can open the Dashboard, Pipelines, Gates, run details, Pull requests, Security, Compliance, Analytics, Activity and Notifications pages and change its own profile, notification and preference settings. Some pages also depend on your plan. For example, Security needs the Team plan, Compliance and SPACE need the Business plan, and the audit log needs Enterprise. See Plans and features.

Org configuration lives on the Organization page (). Org admins open every section. Compliance opens only the Audit log section, because it holds the audit log permission. The Admin Console is a separate tool for the people who run the Prodgator platform and is not part of any role.

Org admin only

These stay with the Org admin role and cannot be added to a custom role:

  • members, roles and invitations
  • identity: SSO, directory sync, verified domains and the break-glass admin
  • API keys and billing
  • integrations and connections, other than security platforms (which Security manages)
  • organization, AI, notification delivery and Slack settings
  • release policy override settings, pull request gate settings, sync and status checks
  • the SPACE survey switch
  • acknowledging provenance changes and managing the provenance allowlist
  • deleting another member's shared AI widget and deleting the organization

Break-glass

Two things carry the name, and they have different owners.

  • Compliance break-glass overrides let blocked deployments to one repository and environment through for a limited time. Compliance and Org admin create them, and answer a deployment that a Block compliance policy governs. Release managers and Security can see them but cannot create them, so the person who ships a release does not also approve an exception to the compliance bar it failed. Release managers keep release policy overrides, which follow the organization's override settings. Only an Org admin changes those settings.
  • The break-glass admin is the one Org admin who can always sign in without SSO when SSO is required. An Org admin chooses them under Organization > Identity. See Directory sync and verified domains.

Pull request approvals

Who can approve a pull request follows the policy bound to it. When a policy names approvers, those people and groups can approve. Otherwise Release manager and Org admin can, and so can a custom role with the approve pull requests permission. See Read and approve.

Sur cette page