Role Permissions
Enterprise Feature
Role Based Access Control is available as an add-on as part of an enterprise plan. If you would like to purchase this feature, please contact us at sales@zuplo.com or reach out to your account manager.
Most enterprise features can be used in a trial mode for a limited time. Feel free to use enterprise features for development and testing purposes.
Without the role-based access control (RBAC) enterprise add-on, every user invited to an account is an Admin. The Developer and Member distinctions below apply only when RBAC is enabled.
A Zuplo account is the top-level container for members and projects. Account roles grant permissions across that container and can also grant access to its projects. A project belongs to one Zuplo account, and project roles grant access only to that project.
The following roles are available at the account level:
- Admin: Admins have full access to the account and can manage all aspects of the account, including billing, members, and roles. Admins can also access all projects and environments in the Account.
- Developer: Developers can create and manage projects and environments in the account. They also have wide access to resources such as tunnels, custom domains, API key buckets, etc. Developers can edit preview and development resources, but not production resources.
- Member: Members of an account don't have any account level or project level permissions. Members can be granted project level permissions by an admin.
Projects can have multiple members with different roles. Some account level roles also grant access to project resources. Users can also be assigned project level roles to grant them access to specific project resources.
The following roles are available at the project level:
- Admin: Admins have full access to the project and can manage all aspects of the project, including environment variables, secrets, and members.
- Developer: Developers have access to all preview and development resources in a project. They can't modify production resources.
- Member: Members of a project can view resources in the project but can't modify them.
Account Role Permissions
The following table outlines the permissions granted directly by each Zuplo account role.
| Resource | Action | Admin | Developer | Member |
|---|---|---|---|---|
| Account | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ✅ | |
| Projects | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ❌ | |
| AI Providers | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ❌ | |
| AI Teams | Manage | ✅ | ❌ | ❌ |
| View | ✅ | ❌ | ❌ | |
| AI Apps | Manage | ✅ | ❌ | ❌ |
| View | ✅ | ❌ | ❌ | |
| Custom Domains | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ❌ | |
| Tunnels | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ❌ | |
| Zuplo API Keys | Edit (All Keys) | ✅ | ❌ | ❌ |
| View (All Keys) | ✅ | ❌ | ❌ | |
| Zuplo API Keys | Edit (Own Keys) | ✅ | ✅ | ❌ |
| View (Own Keys) | ✅ | ✅ | ❌ | |
| Billing | Manage | ✅ | ❌ | ❌ |
| Usage | View | ✅ | ✅ | ❌ |
| Members | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ❌ |
Project Role Permissions
The following table outlines the permissions granted directly by each Zuplo project role.
| Resource | Environment | Action | Admin | Developer | Member |
|---|---|---|---|---|---|
| Project | Edit | ✅ | ❌ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| AI Providers | Edit | ✅ | ❌ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| AI Teams | Manage | ✅ | ❌ | ❌ | |
| View | ✅ | ❌ | ❌ | ||
| AI Apps | Manage | ✅ | ❌ | ❌ | |
| View | ✅ | ❌ | ❌ | ||
| Environment | Production | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ✅ | ||
| Deploy | ✅ | ❌ | ❌ | ||
| Preview | Edit | ✅ | ✅ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| Deploy | ✅ | ✅ | ❌ | ||
| Development | Edit | ✅ | ✅ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| Deploy | ✅ | ✅ | ❌ | ||
| Environment Variables | Production | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ✅ | ||
| Preview | Edit | ✅ | ✅ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| Development | Edit | ✅ | ✅ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| Source Control | N/A | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ✅ | ||
| Members | N/A | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ✅ | ||
| Custom Domains | N/A | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ✅ | ||
| Logs | Production | View | ✅ | ✅ | ❌ |
| Preview | View | ✅ | ✅ | ✅ | |
| Development | View | ✅ | ✅ | ✅ | |
| Builds | Production | View | ✅ | ✅ | ✅ |
| Preview | View | ✅ | ✅ | ✅ | |
| Development | View | ✅ | ✅ | ✅ | |
| Analytics | Production | View | ✅ | ✅ | ✅ |
| Preview | View | ✅ | ✅ | ✅ | |
| Development | View | ✅ | ✅ | ✅ | |
| API Key Buckets | Production | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ✅ | ||
| Preview | Edit | ✅ | ✅ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| Development | Edit | ✅ | ❌ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| Monetization Buckets | Production | Edit | ✅ | ❌ | ❌ |
| View | ✅ | ✅ | ✅ | ||
| Preview | Edit | ✅ | ✅ | ❌ | |
| View | ✅ | ✅ | ✅ | ||
| Development | Edit | ✅ | ❌ | ❌ | |
| View | ✅ | ✅ | ✅ |
The AI Teams and AI Apps rows show project-wide access granted directly by a Zuplo account or Zuplo project role. A team role can grant additional access to a specific team and its apps, but only when the user also has permission to view the associated Zuplo project. A team Admin can manage the team's settings, members, and apps, while a team Member can access its apps. AI provider permissions come only from the user's Zuplo account or Zuplo project role; team membership doesn't grant provider access.