PUBLIC ALPHABiztraak is now in public alpha. Share feedback
Biztraak
Teams & Access
Members Roles Billing Accounts White-Labelling

Roles

Biztraak uses team-level roles to determine what members can see and do. A role is a set of permissions for areas such as projects, components, deployments, users, billing, Marketplace publishing, and compliance workflows.

How permissions work

  • Roles are assigned through the team member and role-management workflows.
  • Permissions are evaluated for the current team before the platform returns or changes team-owned data.
  • Most capability areas have separate create, read, update, and delete permissions. some also have execute or approval permissions.
  • The AdminPermission flag provides elevated team administration where the workflow requires it.
  • Project-component ownership and explicit component grants can further affect access to restricted components.

The exact role names and permission combinations depend on the roles configured for your team. Do not assume that a role named “Developer”, “Viewer”, or “Admin” has the same permissions in every team.

Manage roles

  1. Open the team settings or member-management area.
  2. Review the roles available to the team.
  3. Assign the least-privileged role that supports the member’s work.
  4. Review the affected project, component, deployment, and billing permissions before saving.

Members may need separate permissions for related resources. For example, permission to read project components does not automatically grant permission to read team users, billing accounts, or service providers.

Recommended access practices

  • Start with read access and add write or execute permissions only when needed.
  • Separate deployment, billing, user-management, and compliance responsibilities where possible.
  • Review roles when responsibilities change or a contractor leaves the team.
  • Use service accounts with narrowly scoped permissions for automation.
  • Review audit records for unexpected access or administrative changes.

See Members, Authorization, and Audit Logs for related access workflows.