In this section
User Roles in Console
Console assigns roles at two levels:
- A platform role applies across Console. Every account is either a Platform User or Platform Admin.
- An organization role applies to one organization. A user can belong to multiple organizations and have a different role in each one.
A Platform Admin can administer every organization without an organization role. Feature flags, subscription limits, and connected-tool permissions can still affect which features are available.
Platform Roles
Platform Admin
Platform Admin is intended for platform engineers who operate Console and administer the entire SmoothGlue platform. It includes every Organization Admin capability in every organization, without requiring separate organization roles.
Platform User
Platform User is the standard role for a Console account. It allows a user to sign in and manage their own profile, but it does not provide organization access or administrative capabilities on its own.
To use an organization, a Platform User must also have an organization role for that organization.
| Task | Platform Admin | Platform User |
|---|---|---|
| Manage their own profile | Yes | Yes |
| View and use organization resources | Yes1 | Yes2 |
| Create and manage organizations and platform users | Yes | No |
| Manage members, roles, teams, projects, and deployments | Yes1 | No |
| Discover and open platform tools | Yes | No |
| Repair supported Console resources | Yes | No |
| Monitor Console status and platform health | Yes | No |
Organization Roles
Organization roles apply only to the organization where they are assigned.
Organization Admin
Organization Admin is intended for organization owners or leads who manage an organization's members and resources. It does not allow the user to manage other organizations, create or manage platform users, assign the Platform Admin role, monitor platform-wide health, or change platform-level settings.
Organization Privileged
Organization Privileged is intended for users who need standard Console access and elevated access in supported connected tools.
Organization User
Organization User is intended for users who need to view and use an organization's resources without administering them. Access within connected tools depends on the permissions provided by those tools and the user's team memberships.
| Task | Organization Admin | Organization Privileged | Organization User |
|---|---|---|---|
| View members, projects, teams, tools, and deployments | Yes | Yes | Yes |
| Add, update, and remove organization members | Yes | No | No |
| Assign organization roles | Yes | No | No |
| Create and manage teams and team membership | Yes | No | No |
| Create, configure, and delete projects | Yes | No | No |
| Add and remove project tool links | Yes | No | No |
| Create, update, and remove deployments | Yes | No | No |
| Create and manage Data Mesh resources | Yes | No | No |
Organization Privileged and Organization User intentionally have the same permissions in Console. Their access can differ in connected tools; those mappings are documented separately.