Docs Home
Viewing docs for
BYOCNot available for Self-Managed

Managing Access

On this page

Ververica Cloud uses two kinds of teams to control access: Organization Teams and Teams.

Organization Teams

Every organization gets four permanent Organization Teams automatically. You can't rename, delete, or create additional ones:

  • Organization Admin: access to overall organization needs.
  • Organization Billing Admin: manages payments and related billing tasks.
  • Organization User Admin: access to user permission management.
  • Organization Workspaces Admin: manages workspaces in an organization.
Access Control tab, Organization Teams list showing all four teams with their descriptions and SSO Groups

Link each Organization Team to an SSO Group so the right people in your identity provider get that access.

Edit Organization Team form, linking the Organization Admin team to an SSO Group
Organization Teams list after linking an SSO Group to the Organization Admin team

Teams

Create as many Teams as you need. For each Team, you:

  1. Give it a name.
  2. Link it to one or more SSO Groups from your identity provider.
  3. Assign it to one or more workspaces, choosing a role (Admin, Editor, or Viewer) for each.

Anyone whose identity-provider group membership matches a linked SSO Group gets that Team's role on the workspaces it's assigned to.

Teams tab, empty state with a Create Team button
Add Team form, with Team Name and SSO Groups fields filled in
Teams tab after creating a Team, showing its name and linked SSO Group

Guests and Invitations

Not everyone who needs workspace access belongs to your organization's SSO. Use guest invitations for external collaborators, contractors, or anyone outside your organization's identity provider.

Guests versus Team Members

A guest doesn't sign in through your organization's SSO and isn't linked to any SSO Group. Their access comes directly from the invitation, and it's limited to the workspace they were invited to. A Team member, by contrast, gets access to every workspace their Team is assigned to, based on their identity-provider group membership.

You invite a guest to a specific workspace and assign them a role: Admin, Editor, or Viewer. That access applies to the invited workspace only, not to the whole organization.

Was this helpful?