Managing Access
On this page
Ververica Cloud uses two kinds of teams to control access: Organization Teams and Teams.
Right after you convert to an organization, your workspaces move across with it and stay listed, but nobody can open one yet. Access to a workspace comes from a Team, so set those up before you expect anyone to get back in.
Organization Teams
Every organization gets four permanent Organization Teams automatically. You can't rename, delete, or create additional ones:
- Organization Admin: access to overall organization needs.
- Organization Billing Admin: manages payments and related billing tasks.
- Organization User Admin: access to user permission management.
- Organization Workspaces Admin: manages workspaces in an organization.

Link each Organization Team to an SSO Group so the right people in your identity provider get that access.


Organization Teams govern the organization itself. They cover creating, editing and deleting workspaces and controlling who reaches them, but they don't grant access to work inside a workspace. Running and editing deployments comes from a Team assigned to that workspace.
Teams
Create as many Teams as you need. For each Team, you:
- Give it a name.
- Link it to one or more SSO Groups from your identity provider.
- Assign it to one or more workspaces, choosing a role (Admin, Editor, or Viewer) for each.
Anyone whose identity-provider group membership matches a linked SSO Group gets that Team's role on the workspaces it's assigned to.



The SSO Group name is free text, and it has to match the group name in your identity provider exactly. Ververica Cloud doesn't check it against your identity provider, so a typo produces no error message: the Team simply never matches anyone.
Ververica Cloud doesn't read the list of groups from your identity provider. Providers expose groups differently, and the list is often sensitive, so you type the names you want to use instead of picking them from a list. Configuring your identity provider to send group membership is part of the SSO setup, described in Creating an Organization and Configuring SSO.
Changes to someone's group membership take effect the next time they sign in. An open session keeps the groups it was issued with.
Someone who signs in through SSO and belongs to no Organization Team sees only the workspaces their Teams are assigned to. The organization administration options don't appear for them.
Guests and Invitations
Not everyone who needs workspace access belongs to your organization's SSO. Use guest invitations for external collaborators, contractors, or anyone outside your organization's identity provider.
Guests versus Team Members
A guest doesn't sign in through your organization's SSO and isn't linked to any SSO Group. Their access comes directly from the invitation, and it's limited to the workspace they were invited to. A Team member, by contrast, gets access to every workspace their Team is assigned to, based on their identity-provider group membership.
You invite a guest to a specific workspace and assign them a role: Admin, Editor, or Viewer. That access applies to the invited workspace only, not to the whole organization.
Guest invitations and role permissions are managed by users who are members of Organization Admin or Organization User Admin Teams.