Teams and roles
How teams own jobs and API keys in CosmicAC, and what the platform administrator, team lead, member, and viewer roles can do.
A team is the unit that owns work in CosmicAC. Each team has its own jobs, API keys, and members. A person's role determines which actions they can take in that team.
Your role applies to one team at a time, unless you're a platform administrator.
What a team owns
Jobs and API keys belong to a team, not to the person who created them. Access to a job or API key depends on your role in the team that owns it.
- Jobs: each job belongs to the team that's active when you create it. Team leads and members can update, restart, or delete any job in the team, including a job that a teammate created.
- API keys: each API key belongs to a team. Team members with read access can view a key's name and preview. After you create a key, nobody can retrieve its secret, because CosmicAC stores only a hash of it.
Roles
CosmicAC has one instance-wide role and three team roles. The instance-wide role applies across the deployment. A team role applies only in the team that grants it.
- Platform administrator: a role that manages the whole deployment, including instance-wide settings, and can take every action in every team. A platform administrator doesn't need to be a member of a team to manage it.
- Team lead: a role that manages a team's members and settings, and can take every action available to members and viewers.
- Member: a role that creates and manages jobs and API keys, and has all the read access available to viewers.
- Viewer: a role that has read-only access to the team's jobs, API keys, dashboard, and member list.
Team leads, members, and viewers have permissions only in the teams where they hold those roles. Invitations grant only team roles.
What each role can do
| Action | Platform administrator | Team lead | Member | Viewer |
|---|---|---|---|---|
| View jobs, dashboard, members, and API keys | Every team | Yes | Yes | Yes |
| Create, update, restart, and delete jobs | Every team | Yes | Yes | No |
| Create, rename, and revoke API keys | Every team | Yes | Yes | No |
| Invite members and change their roles | Every team | Yes | No | No |
| Suspend, reactivate, and remove members | Every team | Yes | No | No |
| Edit or archive a team | Every team | Yes | No | No |
| Create teams | Yes | No | No | No |
| Manage model masters, notifications, observability, and feedback | Yes | No | No | No |
A team lead can invite people as team leads, and can make an existing member a team lead.
If your role doesn't permit an action, the web interface turns off the button for that action. To see why, hold the pointer over the button.
Your active team
You work in one team at a time, called your active team. Your active team decides the following:
- Which team owns the jobs and API keys that you create.
- Which jobs and API keys appear in your lists.
- Which role applies to your actions.
The team switcher at the top of the sidebar shows your active team and your role in it. If you belong to more than one team, use the switcher to change your active team. See Switch your active team. If you belong to only one team, the switcher shows that team's name and doesn't open.
A platform administrator can switch to any active team in the deployment, including a team that they aren't a member of.
One account across more than one team
You use the same account for every team that you join. Each team assigns your role separately, so you can be a team lead in one team and a viewer in another.
Your permissions don't combine across teams. When you work in a team, only your role in that team decides which actions you can take. The platform administrator role is the exception, because it applies across the deployment.
Suspended and removed members
A team lead can suspend or remove a member. These actions change the person's membership in that team, not their CosmicAC account.
- Suspended membership: the person keeps their account and their role in the team, but can't access the team until a team lead reactivates their membership. In their team switcher, the team is unavailable and labeled Membership suspended.
- Removed membership: the person loses access to the team immediately and needs a new invitation to rejoin. Their account and their memberships in other teams don't change.
Every team must have at least one active team lead. CosmicAC refuses to suspend, demote, or remove the last active team lead.