From c9bf1deb21f4207bc201ae7c507a3313593df535 Mon Sep 17 00:00:00 2001 From: dannykng Date: Fri, 16 Dec 2022 17:01:54 -0800 Subject: [PATCH] Update Dashboard Access Control doc --- .../pages/guides/platform/access-control.mdx | 100 ++++++++---------- 1 file changed, 45 insertions(+), 55 deletions(-) diff --git a/apps/docs/pages/guides/platform/access-control.mdx b/apps/docs/pages/guides/platform/access-control.mdx index f470d14af9a..9cba90faee5 100644 --- a/apps/docs/pages/guides/platform/access-control.mdx +++ b/apps/docs/pages/guides/platform/access-control.mdx @@ -1,84 +1,74 @@ import Layout from '~/layouts/DefaultGuideLayout' +import { IconCheck } from 'ui' export const meta = { title: 'Access Control', description: 'Roles and permissions at the organization level', } -Supabase provides granular access control features that let you manage permissions across your organizations. - -Within a Supabase organization, a member can have one of the following roles: +Supabase provides granular access controls to manage permissions across your organizations. +For each organization, a member can have one of the following roles: - Owner - Administrator - Developer -A default organization is created for a user when they first sign-in and -assigned the **Owner** role. If the user wants to invite others -to collaborate within the organization, they can visit the organization team -settings (`https://app.supabase.com/org//settings#team`) to send an -invite link to another user's email. The invite expires after 24 hours. - -Invites sent from a SSO account can only be accepted by another SSO account -coming from the same identity provider. This is a security measure that -prevents accidental invites to accounts not managed by your company's -enterprise systems. - -Project level invites are not available at this time. A member of the -organization will be able to access all projects under the organization. If you -wish to restrict access to certain projects, please create another organization -to manage this. +A default organization is created when you first sign in and +you'll be assigned the **Owner** role. +Each member can access all projects under the organization. +Project level invites are not available at this time. +Create a separate organization if you need to restrict access to certain projects. ## Manage team members -You can invite your team members into your organizations to collaborate on projects. - - +To invite others to collaborate, visit your organization's team settings in the +[Dashboard](https://app.supabase.com/projects) to send an invite link to +another user's email. The invite expires after 24 hours. ### Permissions across roles [#permission-across-roles] The table below shows the corresponding permissions for each available role you can assign a team member in the Dashboard. -| Permissions | Owner | Administrator | Developer | -| ------------------------ | ----- | ------------- | --------- | +| Permissions | Owner | Administrator | Developer | +| ------------------------ | ----------------------- | ----------------------- | ----------------------- | | **Organization** | -| Change organization name | ✅ | | | -| Delete organization | ✅ | | | +| Change organization name | | | | +| Delete organization | | | | | **Members** | -| Add an Owner | ✅ | | | -| Remove an Owner | ✅ | | | -| Add an Administrator | ✅ | ✅ | | -| Remove an Administrator | ✅ | ✅ | | -| Add a Developer | ✅ | ✅ | | -| Remove a Developer | ✅ | ✅ | | -| Revoke an invite | ✅ | ✅ | | -| Resend an invite | ✅ | ✅ | | -| Accept an invite[^1] | ✅ | ✅ | ✅ | +| Add an Owner | | | | +| Remove an Owner | | | | +| Add an Administrator | | | | +| Remove an Administrator | | | | +| Add a Developer | | | | +| Remove a Developer | | | | +| Revoke an invite | | | | +| Resend an invite | | | | +| Accept an invite[^1] | | | | | **Billing** | -| Read invoices | ✅ | ✅ | ✅ | -| Read billing email | ✅ | ✅ | ✅ | -| Change billing email | ✅ | | | -| View subscription | ✅ | ✅ | ✅ | -| Update subscription | ✅ | ✅ | | -| Read billing address | ✅ | ✅ | ✅ | -| Update billing address | ✅ | ✅ | | -| Read tax codes | ✅ | ✅ | ✅ | -| Update tax codes | ✅ | ✅ | | -| Read payment methods | ✅ | ✅ | ✅ | -| Update payment methods | ✅ | ✅ | | +| Read invoices | | | | +| Read billing email | | | | +| Change billing email | | | | +| View subscription | | | | +| Update subscription | | | | +| Read billing address | | | | +| Update billing address | | | | +| Read tax codes | | | | +| Update tax codes | | | | +| Read payment methods | | | | +| Update payment methods | | | | | **Projects** | -| Create a project | ✅ | ✅ | | -| Delete a project | ✅ | ✅ | | -| Update a project | ✅ | ✅ | | -| Pause a project | ✅ | ✅ | | -| Resume a project | ✅ | ✅ | | -| Restart a project | ✅ | ✅ | ✅ | +| Create a project | | | | +| Delete a project | | | | +| Update a project | | | | +| Pause a project | | | | +| Resume a project | | | | +| Restart a project | | | | [^1]: - If the invite was sent from a SSO account, it can only be accepted from - a user signed in via the same identity provider. + Invites sent from a SSO account can only be accepted by another SSO account + coming from the same identity provider. This is a security measure that + prevents accidental invites to accounts not managed by your company's + enterprise systems. export const Page = ({ children }) =>