Roles and permissions
Control who can do what in your Gateway organization with built-in and custom roles
Every member of a Gateway organization holds exactly one role, a bundle of permissions. Use the four built-in roles, or a custom role when a team needs a different mix.
Built-in roles
Built-in roles can’t be edited or deleted; for a different permission set, create a custom role.
Reference
Most resources have View and Manage permissions; logs, traces, audit trail, and request tester are view-only. The same matrix appears under Settings → Roles.
Custom roles
With Manage roles, click Add custom role under Settings → Roles in the dashboard to add an editable column to the matrix. For example, a “Routing editor” role might hold Manage routing, View projects, and View API keys.
- Role names must be unique within the organization
- A role with members can’t be deleted until you reassign them
- Roles are flat, with no inheritance
Assign roles to members
Invite members and change their roles under Settings → Organization, with Manage users.
- An invitation carries the role granted on acceptance and expires after 7 days. Resending restarts the 7 days.
- A role change takes effect immediately and records the old and new role in the audit trail
- You can’t remove the last Admin of an organization
Every role and membership change is audited, role edits with a field-level diff.