Docs Home
Viewing docs for
BYOCNot available for Self-Managed

Managing Access

On this page

Ververica Cloud uses two kinds of teams to control access: Organization Teams and Teams.

Right after you convert to an organization, your workspaces move across with it and stay listed, but nobody can open one yet. Access to a workspace comes from a Team, so set those up before you expect anyone to get back in.

Organization Teams

Every organization gets four permanent Organization Teams automatically. You can't rename, delete, or create additional ones:

  • Organization Admin: access to overall organization needs.
  • Organization Billing Admin: manages payments and related billing tasks.
  • Organization User Admin: access to user permission management.
  • Organization Workspaces Admin: manages workspaces in an organization.
Access Control tab, Organization Teams list showing all four teams with their descriptions and SSO Groups

Link each Organization Team to an SSO Group so the right people in your identity provider get that access.

Edit Organization Team form, linking the Organization Admin team to an SSO Group
Organization Teams list after linking an SSO Group to the Organization Admin team

Organization Teams govern the organization itself. They cover creating, editing and deleting workspaces and controlling who reaches them, but they don't grant access to work inside a workspace. Running and editing deployments comes from a Team assigned to that workspace.

Teams

Create as many Teams as you need. For each Team, you:

  1. Give it a name.
  2. Link it to one or more SSO Groups from your identity provider.
  3. Assign it to one or more workspaces, choosing a role (Admin, Editor, or Viewer) for each.

Anyone whose identity-provider group membership matches a linked SSO Group gets that Team's role on the workspaces it's assigned to.

Teams tab, empty state with a Create Team button
Add Team form, with Team Name and SSO Groups fields filled in
Teams tab after creating a Team, showing its name and linked SSO Group

Ververica Cloud doesn't read the list of groups from your identity provider. Providers expose groups differently, and the list is often sensitive, so you type the names you want to use instead of picking them from a list. Configuring your identity provider to send group membership is part of the SSO setup, described in Creating an Organization and Configuring SSO.

Changes to someone's group membership take effect the next time they sign in. An open session keeps the groups it was issued with.

Someone who signs in through SSO and belongs to no Organization Team sees only the workspaces their Teams are assigned to. The organization administration options don't appear for them.

Guests and Invitations

Not everyone who needs workspace access belongs to your organization's SSO. Use guest invitations for external collaborators, contractors, or anyone outside your organization's identity provider.

Guests versus Team Members

A guest doesn't sign in through your organization's SSO and isn't linked to any SSO Group. Their access comes directly from the invitation, and it's limited to the workspace they were invited to. A Team member, by contrast, gets access to every workspace their Team is assigned to, based on their identity-provider group membership.

You invite a guest to a specific workspace and assign them a role: Admin, Editor, or Viewer. That access applies to the invited workspace only, not to the whole organization.

Was this helpful?