User Roles
Overview
OpsWorker uses role-based access control with two roles: Admin and ReadOnly (shown in the UI as "ReadOnly"). A user has one role within the organization.
Permissions
| Capability | Admin | ReadOnly |
|---|---|---|
| View investigations, dashboards, and insights | Yes | Yes |
| Use AI Chat | Yes | Yes |
| Provide investigation feedback | Yes | Yes |
| Create and rename clusters | Yes | Yes |
| Delete a cluster (only while status is PENDING) | Yes | No |
| Create, update, delete alert rules | Yes | No |
| Create, update, delete integrations | Yes | No |
| Configure Slack namespace routing | Yes | No |
| Invite or delete users | Yes | No |
| Change a user's role | Yes | No |
| Move a user to a different workspace | Yes | No |
| Create, rename, delete workspaces | Yes | No |
| Rename the organization | Yes | No |
A user cannot change their own role or move their own workspace, regardless of role.
Role Descriptions
Admin
Full access, including configuration and management:
- Create, rename, and delete workspaces; move users between workspaces
- Create and rename clusters; delete a cluster while it is still PENDING
- Create, update, and delete alert rules and integrations
- Configure Slack namespace routing
- Invite and delete users, and change user roles
- Rename the organization
Recommended for: team leads, SRE managers, and platform engineers who manage the OpsWorker setup.
ReadOnly
Read access across the organization, plus the ability to create and rename clusters:
- View investigation results and details
- Use AI Chat to query clusters
- Provide feedback on investigations
- View operational insights and alert data
- Create and rename clusters
Recommended for: on-call engineers, developers, and team members who use OpsWorker for daily operations.
Changing Roles
Only an Admin can change another user's role:
- Go to Account Settings -> User Management
- Find the user
- Change their role
- Save
Next Steps
- Invite Users - Add team members
- Workspace Assignment - Control access scope