A role is a set of permissions. Every member holds one, and it decides which parts of the Burrow they can see and what they can do there. Roles are listed under the members on the Members page.
How permissions work#
Permissions are set per area of the Burrow, and each area has three: read, write, and delete. Read lets a member see an area, write lets them create and change things in it, and delete lets them remove things. A member without any permission for an area doesn't see it at all.
Group | Areas |
|---|---|
Contents | Projects and secrets, Machines, Machine tokens, Audit log, Webhooks, Burrow note. |
Operating | Members and roles, Other members' sessions, Console. |
Configuration | One area for each section of Burrow Settings: Burrow config, Display, Remote access, Network, Security, Backups, and Encryption and keys. |
Everyone can always see their own sessions and account, whatever their role. Other members' sessions is only for seeing and signing out somebody else's devices.
Built-in roles#
Every Burrow comes with three roles. They can't be edited or deleted, so they mean the same thing in every Burrow.
Role | Grants |
|---|---|
Administrator | Read, write, and delete on projects and secrets, machines, machine tokens, members and roles, webhooks, and the Burrow note. Read on the audit log. |
Developer | Read and write on projects and secrets, machines, and machine tokens, without deleting any of them. Read on the Burrow note. |
Member | Read on the Burrow note. Someone on this role can sign in and see the overview. |
None of the built-in roles reach Burrow Settings, other members' sessions, or the Console. Those stay with the Owner unless a custom role grants them.
To see exactly what any role grants, open its row menu and select View scope.
Creating a custom role#
Select + at the top of the Roles list.
Name the role. Each name can only be used once in a Burrow.
Tick read, write, or delete for each area it should grant.
Select Create role.
You can only grant permissions you hold yourself. Boxes for anything beyond your own access are greyed out.
Custom roles are part of the paid plans. On a plan without them, the Roles list still shows them, but they can't be created, edited, or assigned, and members on a custom role have no access until the plan includes them again.
Editing and deleting#
Open a custom role's row menu and select Edit to change its name or permissions. The change applies to everyone on the role.
Select Delete to remove it. If anyone holds the role, choose the role they move to first. Member is selected to start with. Deleting stays available on every plan.
You can't edit or delete a role that grants more than you hold, and moving members onto another role follows the same rule as assigning it.
When changes take effect#
The Burrow checks each member's permissions with RatelKey on every request, so a changed role applies to everyone holding it on their next action. Creating, editing, and deleting roles are recorded in the audit log.