Beskos

Administration

Roles and permissions

Four roles, eighteen permissions and per-user exceptions.

Updated:

Contents

Each user holds one role. Individual permissions may be granted or withdrawn in addition to the role, so that a specific capability can be assigned without changing the role.

Roles

  • Owner — full permissions, including deletion of the organisation. At least one owner exists at all times.
  • Admin — full permissions, excluding actions applied to an owner.
  • Member — access to resources shared with the user. The standard role.
  • Billing — invoices, plan, usage and the user list.

Scope of the Admin role

The Admin role holds the full permission set. The hierarchy is enforced separately: an administrator cannot act on an owner. Individual permissions may be withdrawn from a specific administrator by exception.

Per-user exceptions

Administration → Users → the shield icon. A permission not included in the role may be granted, and a permission included in the role may be withdrawn. The resulting set is enforced by the server, not only by the interface.

Destructive permissions

Domain removal and mailbox deletion are controlled by separate permissions, held apart from routine administration. Account creation and password resets do not require them.