Roles¶
Everysk's Enterprise accounts include a governance feature that enables fine-grained access control through Roles and Users. Roles define what a user is allowed to see and do across the platform, and users can be assigned different roles depending on the workspace they are operating in.
Permission Levels¶
The table below describes what each permission level means across all resource types:
| Permission | Description |
|---|---|
READ |
View and list resources. Does not allow creating, modifying, or deleting. |
EDIT |
Full write access — create, update, and delete resources. Includes READ. |
RUN |
Execute the resource (Workflows, Apps). Does not allow editing or creating new ones. |
DEVELOPER |
Access developer tools on workers and view workflow source code (Workflows only). |
PREVIEW |
Preview the output that would be generated from the resource (Report Templates only). |
VIEW USER |
View audit log entries associated with the authenticated user only. |
VIEW ALL USERS |
View audit log entries for all users in the account. |
Roles¶
A role is a named set of permissions. When creating or editing a role, permissions are organized across four categories:
Governance — controls access to role and user management:
| Resource | Available Permissions |
|---|---|
| Roles | READ / EDIT |
| Users | READ / EDIT |
Security — controls access to audit and monitoring features:
| Resource | Available Permissions |
|---|---|
| Audit Logs | VIEW USER / VIEW ALL USERS |
Account Scope — global entities that are not tied to a specific workspace:
| Resource | Available Permissions |
|---|---|
| Integrations | READ / EDIT |
| Custom Indexes | READ / EDIT |
| Private Securities | READ / EDIT |
| Apps | READ / RUN / EDIT |
| Workspaces | READ / EDIT |
| For Developer Templates | READ / EDIT |
| API | READ / EDIT |
| Secrets | READ / EDIT |
| OAuth2 | READ / EDIT |
Entities — workspace-scoped resources:
| Resource | Available Permissions |
|---|---|
| Workflows | READ / RUN / EDIT / DEVELOPER |
| Report Templates | READ / PREVIEW / EDIT |
| Reports | READ / EDIT |
| Portfolios | READ / EDIT |
| Datastores | READ / EDIT |
| Files | READ / EDIT |
Users¶
Each user is assigned a Default Role that applies across all workspaces. Additionally, users can be assigned workspace-specific roles via Roles by Workspace, which override the default role when the user operates within that particular workspace.
| Field | Description |
|---|---|
Corporate Email |
The user's corporate email address. Cannot be changed after creation. |
First Name |
The user's first name. |
Last Name |
The user's last name. |
Company Name |
The name of the company the user belongs to. |
Default Role |
The role applied to the user across all workspaces where no workspace-specific role is configured. |
Status |
The user's account status (e.g., active or inactive). |
Roles by Workspace |
One or more workspace-role pairs that override the default role for each specified workspace. |
Labels |
Optional key-value metadata tags that can be attached to the user for custom categorization. |
To restrict a user's access to specific workspaces only, set a role with no permissions as the Default Role. With this configuration, the user has no platform access by default and must receive a workspace-specific role in order to perform any action.
API requests are checked against the role the user has in the workspace given by the workspace parameter.