CosmicAC Logo

Teams and roles

How teams own jobs and API keys in CosmicAC, and what the platform administrator, team lead, member, and viewer roles can do.

A team is the unit that owns work in CosmicAC. Each team has its own jobs, API keys, and members. A person's role determines which actions they can take in that team.

Your role applies to one team at a time, unless you're a platform administrator.

What a team owns

Jobs and API keys belong to a team, not to the person who created them. Access to a job or API key depends on your role in the team that owns it.

  • Jobs: each job belongs to the team that's active when you create it. Team leads and members can update, restart, or delete any job in the team, including a job that a teammate created.
  • API keys: each API key belongs to a team. Team members with read access can view a key's name and preview. After you create a key, nobody can retrieve its secret, because CosmicAC stores only a hash of it.

Roles

CosmicAC has one instance-wide role and three team roles. The instance-wide role applies across the deployment. A team role applies only in the team that grants it.

  • Platform administrator: a role that manages the whole deployment, including instance-wide settings, and can take every action in every team. A platform administrator doesn't need to be a member of a team to manage it.
  • Team lead: a role that manages a team's members and settings, and can take every action available to members and viewers.
  • Member: a role that creates and manages jobs and API keys, and has all the read access available to viewers.
  • Viewer: a role that has read-only access to the team's jobs, API keys, dashboard, and member list.

Team leads, members, and viewers have permissions only in the teams where they hold those roles. Invitations grant only team roles.

What each role can do

ActionPlatform administratorTeam leadMemberViewer
View jobs, dashboard, members, and API keysEvery teamYesYesYes
Create, update, restart, and delete jobsEvery teamYesYesNo
Create, rename, and revoke API keysEvery teamYesYesNo
Invite members and change their rolesEvery teamYesNoNo
Suspend, reactivate, and remove membersEvery teamYesNoNo
Edit or archive a teamEvery teamYesNoNo
Create teamsYesNoNoNo
Manage model masters, notifications, observability, and feedbackYesNoNoNo

A team lead can invite people as team leads, and can make an existing member a team lead.

If your role doesn't permit an action, the web interface turns off the button for that action. To see why, hold the pointer over the button.

Your active team

You work in one team at a time, called your active team. Your active team decides the following:

  • Which team owns the jobs and API keys that you create.
  • Which jobs and API keys appear in your lists.
  • Which role applies to your actions.

The team switcher at the top of the sidebar shows your active team and your role in it. If you belong to more than one team, use the switcher to change your active team. See Switch your active team. If you belong to only one team, the switcher shows that team's name and doesn't open.

A platform administrator can switch to any active team in the deployment, including a team that they aren't a member of.

One account across more than one team

You use the same account for every team that you join. Each team assigns your role separately, so you can be a team lead in one team and a viewer in another.

Your permissions don't combine across teams. When you work in a team, only your role in that team decides which actions you can take. The platform administrator role is the exception, because it applies across the deployment.

Suspended and removed members

A team lead can suspend or remove a member. These actions change the person's membership in that team, not their CosmicAC account.

  • Suspended membership: the person keeps their account and their role in the team, but can't access the team until a team lead reactivates their membership. In their team switcher, the team is unavailable and labeled Membership suspended.
  • Removed membership: the person loses access to the team immediately and needs a new invitation to rejoin. Their account and their memberships in other teams don't change.

Every team must have at least one active team lead. CosmicAC refuses to suspend, demote, or remove the last active team lead.

Next steps

On this page