Skip to main content
Version: latest

Project Roles

Palette provides the following Project roles out-of-the-box. These roles are predefined and cannot be modified. You can assign these roles to users and teams to manage the resources within the project scope. The roles are categorized based on the resources they can manage. If you need to manage resources across multiple projects, consider using a Tenant role instead.

tip

Create your own custom project role if none of the predefined roles meet your requirements. Refer to the Create a Custom Role guide for more information.

Default Project Roles

Palette comes with a set of immutable predefined Project roles out-of-the-box that you can assign to users or teams. To review the permissions associated with each Project role, click on the role name to expand the list of permissions.

App Deployment

Role NameDescription
App Deployment AdminProvides administrative privilege to perform all the App operations on App resources.
App Deployment EditorAllows the user to perform edit operations on an App but not to create or delete an App.
App Deployment ViewerAllows the user to view all the App resources but not to make modifications.

App Profile

Role NameDescription
App Profile AdminProvides administrative privilege to perform all the App operations on App profile resources.
App Profile EditorAllows the user to perform edit operations on App profiles but not to create or delete an App profile.
App Profile ViewerAllows the user to view all the App profile resources but not to modify them.

Cloud Account

Role NameDescription
Cloud Account AdminAn administrative access to cloud account operations.
Cloud Account EditorAn editor access to cloud account operations.
Cloud Account ViewerA read-only role for cloud account operations.

Cluster

Role NameDescription
Cluster AdminA cluster admin in the Project scope has all the privileges related to the cluster operation.
Cluster EditorA cluster editor in the Project scope has the privileges to update, delete, get, and list cluster resources. This role is not privileged for cluster creation.
Cluster ViewerA cluster viewer in Project scope is a read-only privilege to cluster operations.

Cluster Profile

Role NameDescription
Cluster Profile AdminCluster Profile Admin role has admin privileges to all the cluster profile operations.
Cluster Profile EditorCluster Profile Editor role has privileges to edit and list operations on the cluster profile.
Cluster Profile ViewerCluster Profile Viewer role has read-only privileges to cluster profiles.

Project

Role NameDescription
Project AdminThe Project Admin role is a closure of all the project operations. It is an administrative privilege for the project resources.
Project EditorThe Project Editor role can perform edit operations within a project, but the user is not able to create or delete a project.
Project ViewerThe Project Viewer will be able to view all the resources within a project, but is not privileged to make modifications.

Project Cluster Group

Role NameDescription
Project Cluster Group AdminProvides administrative privilege to perform all the operations on the cluster group resources.
Project Cluster Group EditorAllows the user to perform edit operations on a cluster group but not to create or delete a cluster group.
Project Cluster Group ViewerAllows the user to view all the cluster group resources but not to modify them.

Virtual Cluster

Role NameDescription
Virtual Cluster AdminProvides administrative privilege to perform all virtual cluster operations on App resources.
Virtual Cluster EditorAllows the user to perform edit operations on a virtual cluster but not to create or delete a virtual cluster.
Virtual Cluster ViewerAllows the user to view all the virtual cluster resources but not to modify them.

Virtual Machine

Role NameDescription
Virtual Machine AdminProvides administrative privilege to perform all the virtual machine operations.
Virtual Machine Power UserProvides the user with the ability to most of the virtual machine operations.
Virtual Machine UserProvides the user with the ability to perform non-destructive operations on virtual machines.
Virtual Machine ViewerProvides the user with the ability to view virtual machines.

Workspace

Role NameDescription
Workspace AdminAdministrator role to workspace operations.
Workspace EditorEditor role to workspace operations.

Resources