Skip to main content
Version: latest

Tenant Roles

Palette provides the following Tenant roles out-of-the-box. These roles are predefined and cannot be modified. You can assign these roles to users and teams. The roles are categorized based on the resources they can manage. Each of these roles is scoped at the tenant level. This means the permissions granted to a user or team span across all projects. If you need to narrow the scope down to a single project or a handful of projects, consider using a Project role instead.

tip

Create your own custom tenant role if none of the predefined roles meet your requirements. Refer to the Create a Custom Role guide for more information.

Default Tenant Roles

Palette comes with a set of immutable predefined Tenant roles out-of-the-box that you can assign to users or teams. To review the permissions associated with each Tenant role, click on the role name to expand the list of permissions.

Admin

Role NameDescription
Tenant AdminGrants access to all resources in all projects.
Tenant ViewerProvides a read only access to all the project resources.

Cluster Group

Role NameDescription
Tenant Cluster Group AdminAllows the user to create and manage cluster groups in all projects.
Tenant Cluster Group EditorAllows the user to view, access, and update cluster groups in all projects.
Tenant Cluster Group ViewerGrants read-only access to cluster groups in all projects.

Cluster Profile

Role NameDescription
Tenant Cluster Profile AdminAllows the user to create and manage cluster profiles in all projects.

Project

Role NameDescription
Tenant Project AdminGrants the user complete access to all the project resources. Unlike the Tenant Admin role, this role cannot create projects, users, and teams.

Role

Role NameDescription
Tenant Role AdminThis role allows the user to create, update, and delete roles.

Team

Role NameDescription
Tenant Team AdminThis role grants the user complete access to all the team resources.

User

Role NameDescription
Tenant User Admin RoleThis role grants the user complete access to all user operations.

Resources