Roles and Permissions
Understand the current project roles in Lleverage and how organisation ownership affects project access.
Lleverage separates organisation membership from project roles. A person's organisation status determines their relationship to the organisation; their project role determines what they can do inside a project.
Current project roles
Owner
Owners administer the project. They can manage project membership and owner-only project configuration, including Project Settings.
Builder
Builders create and improve operational behaviour. They can build and change Workflows and can configure several Control surfaces that require Builder-level access, such as Agent schedules, Secrets, Variables and Metrics.
Project Settings itself is owner-only. A Builder may be able to open that page but will see a permission message instead of editable settings.
Operator
Operators use the operational surfaces of the project rather than configuring it. They work through the Agent, Workflow apps and Requests. The Control section is not shown to Operator-only project users.
There is no current project Member role
Member remains an organisation role and can appear in legacy project data, but it is retired as a current project role. New project access should be described using Owner, Builder or Operator.
Organisation Owners have broader authority
Organisation ownership is separate from the project-role row. Organisation Owners are treated as project Owners across several administration paths and can therefore administer projects without needing an explicit project membership in every case.
This matters when diagnosing access: looking only at the project member list does not tell the whole story for an organisation Owner.
Use least privilege
Give people the lowest role that lets them do the work they are responsible for. Keep Owner access limited, use Builder for people actively configuring the system, and use Operator for people running the operation without changing its configuration.
Enterprise SSO authenticates identity; it does not replace the organisation and project access model. See Enterprise SSO Setup for configuration details.
Last updated
Was this helpful?