Roles

13 roles defined in this workspace

IAM Admin

2 users assigned

Full access to identity and access management platform. Can provision, modify, and revoke any user role or permission.

Permissions

iam:readiam:writeiam:deleteuser:managerole:manageaudit:readpolicy:write
Created 2023-06-012 / — users

IAM Engineer

3 users assigned

Read and write access to IAM configurations. Cannot delete roles or manage critical policies.

Permissions

iam:readiam:writeuser:readrole:readaudit:read
Created 2023-06-013 / — users

Developer – Prod Access

6 users assigned

Elevated developer access including read access to production environments and deployment approval rights.

Permissions

repo:readrepo:writedeploy:prod-readdeploy:stagingci:triggersecrets:read
Created 2023-08-156 / — users

Developer – Non-Prod

14 users assigned

Standard developer access scoped to non-production environments only.

Permissions

repo:readrepo:writedeploy:stagingci:trigger
Created 2023-08-1514 / — users

CI/CD Pipeline Operator

4 users assigned

Access to manage and operate CI/CD pipelines across all environments, including production deployment gates.

Permissions

ci:readci:writeci:triggerdeploy:proddeploy:staginginfra:read
Created 2023-09-014 / — users

Service Desk Tier 1

11 users assigned

Basic support access: read-only user lookup, password reset initiation, and ticket management.

Permissions

user:readticket:readticket:writepassword:reset
Created 2023-06-0111 / — users

Service Desk Tier 2

5 users assigned

Elevated support access including group membership changes and escalation handling.

Permissions

user:readuser:writeticket:readticket:writegroup:writepassword:reset
Created 2023-06-015 / — users

NOC Operator

8 users assigned

Read access to infrastructure monitoring, alerting dashboards, and incident ticketing.

Permissions

monitoring:readalerts:readticket:writeinfra:read
Created 2023-07-108 / — users

NOC Senior Operator

3 users assigned

NOC operator access plus ability to acknowledge alerts, run remediation runbooks, and escalate incidents.

Permissions

monitoring:readmonitoring:writealerts:readalerts:writeticket:writeinfra:readrunbook:execute
Created 2023-07-103 / — users

SOC Analyst

7 users assigned

Access to SIEM, threat intelligence feeds, and incident response tooling for security event investigation.

Permissions

siem:readthreat-intel:readticket:writeendpoint:readlog:read
Created 2023-07-017 / — users

SOC Lead Analyst

2 users assigned

Full SOC tooling access including alert triage, containment actions, and forensic log access.

Permissions

siem:readsiem:writethreat-intel:readticket:writeendpoint:readendpoint:isolatelog:readforensics:read
Created 2023-07-012 / — users

Issuer Services Manager

3 users assigned

Full access to issuer client configurations, transaction data, and exception handling workflows.

Permissions

issuer:readissuer:writetransactions:readexceptions:writereporting:readclient-config:write
Created 2023-10-013 / — users

Issuer Services Read-Only

9 users assigned

Read-only access to issuer dashboards and reports. No ability to modify client configurations.

Permissions

issuer:readreporting:read
Created 2023-10-019 / — users