access users and teams.md

Access, users and teams

MK.IO uses role-based access control (RBAC) to manage who can access resources and what they can do. Users are assigned permissions through teams, allowing you to control access to projects across your organization.

Concepts

The first user in an organization is automatically granted Administrators access. Administrators have full control over the system, including the ability to invite users and create new teams.

Manage teams

Project access is granted to users through teams. By default, every organization has two predefined teams: Administrators and Everyone.

Create a team

Info: This action is only available to members of the Administrators team.

  1. From the profile drop-down menu in the top right corner, navigate to Organization Settings, then select Access Management.
  2. From the Teams tab, click Create Team, then enter a name and a description.
  3. Click the team name to open it and manage members, projects, and access levels.

Edit team members

Info: This action is only available to members of the Administrators team, or Team admins for the relevant team.

From the Teams tab, select a team. Use the Add user button to add members. To set a user as a Team admin or remove them from the team, select the three-dot menu to the right of their username.

Edit project access for a team

Info: This action is only available to members of the Administrators team.

  1. From the Teams tab, select a team.
  2. In the right-hand pane, add the projects the team should have access to.
  3. For each project, select the access level:
    • Reader: read-only access.
    • User: full access to create and modify objects in the project.

Edit team details or delete a team

Info: This action is only available to members of the Administrators team.

From the Teams tab, select the three vertical dots in the top right corner, then select the appropriate action.

Manage access with the API

Use the Users and teams API Guide to manage organization membership and team access through the Management API.