Managing Access
On this page
Ververica Cloud uses two kinds of teams to control access: Organization Teams and Teams.
Organization Teams
Every organization gets four permanent Organization Teams automatically. You can't rename, delete, or create additional ones:
- Organization Admin: access to overall organization needs.
- Organization Billing Admin: manages payments and related billing tasks.
- Organization User Admin: access to user permission management.
- Organization Workspaces Admin: manages workspaces in an organization.

Link each Organization Team to an SSO Group so the right people in your identity provider get that access.


Teams
Create as many Teams as you need. For each Team, you:
- Give it a name.
- Link it to one or more SSO Groups from your identity provider.
- Assign it to one or more workspaces, choosing a role (Admin, Editor, or Viewer) for each.
Anyone whose identity-provider group membership matches a linked SSO Group gets that Team's role on the workspaces it's assigned to.



Guests and Invitations
Not everyone who needs workspace access belongs to your organization's SSO. Use guest invitations for external collaborators, contractors, or anyone outside your organization's identity provider.
Guests versus Team Members
A guest doesn't sign in through your organization's SSO and isn't linked to any SSO Group. Their access comes directly from the invitation, and it's limited to the workspace they were invited to. A Team member, by contrast, gets access to every workspace their Team is assigned to, based on their identity-provider group membership.
You invite a guest to a specific workspace and assign them a role: Admin, Editor, or Viewer. That access applies to the invited workspace only, not to the whole organization.
Guest invitations and role permissions are managed by users who are members of Organization Admin or Organization User Admin Teams.