Skip to main content

Teams and IAM

How permissions, ownership, and collaboration work.

Teams and IAM

Teams group users and own resources. IAM (identity and access management) controls what each team member can do, read, write, delete, deploy. Every resource in Vantage belongs to a team, and every action is authorized against that team's permissions.

Teams

A team is a group of users that share access to a set of resources, clusters, workspaces, storage, jobs. Teams are the ownership boundary: when you create a resource, it belongs to your current team. Other teams can't see it unless you explicitly share it.

The Teams page lists every team you're a member of. Team admins can add and remove members, and assign roles.

Roles and permissions

Vantage uses role-based access control (RBAC). A role is a set of permissions, create sessions, submit jobs, manage storage, administer teams, that you assign to users within a team. Built-in roles cover Admin, Engineer, and Viewer; team admins can define custom permission sets. For the role inventory and the IAM permission-group inventory, see Teams concepts and IAM concepts.

Resource ownership

Every resource tracks who created it and which team it belongs to. Ownership controls who can modify or delete it. When you leave a team, your personal resources remain, the team admin can reassign ownership if needed.

Cross-references

  • Teams concepts: team-as-ownership-boundary, membership across teams, resource visibility
  • IAM concepts: permission groups, authentication, SCIM provisioning
Ask AI
Ask a question about Vantage Compute...