[{"data":1,"prerenderedAt":737},["ShallowReactive",2],{"docs-user\u002Fpermissions":3,"navigation":600,"docs-surround-user\u002Fpermissions":732},{"id":4,"title":5,"body":6,"description":16,"extension":593,"meta":594,"navigation":595,"path":596,"seo":597,"stem":598,"__hash__":599},"docs\u002F1.user\u002Fpermissions.md","Permissions",{"type":7,"value":8,"toc":580},"minimark",[9,13,17,22,31,36,87,91,96,129,133,210,214,278,286,289,292,295,300,304,307,311,314,318,380,389,393,459,462,466,538,544,548,561,565,572],[10,11,5],"h1",{"id":12},"permissions",[14,15,16],"p",{},"There are three layers of permissions in udCloud: Organisation-level, Project-level, and Server-Wide Administration.",[18,19,21],"h2",{"id":20},"organisations","Organisations",[14,23,24,25,30],{},"Organisation permissions control what a member can do within an organisation. Every member has a set of permissions that can be granted individually or through ",[26,27,29],"a",{"href":28},"organisations#roles","Roles",".",[32,33,35],"h3",{"id":34},"default-roles","Default Roles",[37,38,39,52],"table",{},[40,41,42],"thead",{},[43,44,45,49],"tr",{},[46,47,48],"th",{},"Role",[46,50,51],{},"Description",[53,54,55,67,77],"tbody",{},[43,56,57,64],{},[58,59,60],"td",{},[61,62,63],"strong",{},"Guest",[58,65,66],{},"Can see public projects in the organisation. No access to internal projects or member lists.",[43,68,69,74],{},[58,70,71],{},[61,72,73],{},"Member",[58,75,76],{},"Can see other members and internal projects.",[43,78,79,84],{},[58,80,81],{},[61,82,83],{},"Owner",[58,85,86],{},"Full access to everything in the organisation. Can rename the organisation, set its visibility, and promote other users to Owner. Owners always have all permissions regardless of individual permission settings.",[32,88,90],{"id":89},"available-permissions","Available Permissions",[92,93,95],"h4",{"id":94},"project-permissions","Project Permissions",[37,97,98,107],{},[40,99,100],{},[43,101,102,105],{},[46,103,104],{},"Permission",[46,106,51],{},[53,108,109,119],{},[43,110,111,116],{},[58,112,113],{},[61,114,115],{},"Manage Projects",[58,117,118],{},"Can create, delete and rename projects in the organisation.",[43,120,121,126],{},[58,122,123],{},[61,124,125],{},"View Projects",[58,127,128],{},"Can see projects exist. Without this, projects are hidden but the user may still access scenes or files with appropriate permissions.",[92,130,132],{"id":131},"member-permissions","Member Permissions",[37,134,135,143],{},[40,136,137],{},[43,138,139,141],{},[46,140,104],{},[46,142,51],{},[53,144,145,155,165,175,185,195],{},[43,146,147,152],{},[58,148,149],{},[61,150,151],{},"Invite Members",[58,153,154],{},"Can invite new members to the organisation by email address, and approve or decline requests to join.",[43,156,157,162],{},[58,158,159],{},[61,160,161],{},"Remove Members",[58,163,164],{},"Can remove members from the organisation.",[43,166,167,172],{},[58,168,169],{},[61,170,171],{},"Modify Member Roles",[58,173,174],{},"Can add and remove roles from users (except Owner).",[43,176,177,182],{},[58,178,179],{},[61,180,181],{},"See Roles and Members",[58,183,184],{},"Can view the list of members and roles in the organisation.",[43,186,187,192],{},[58,188,189],{},[61,190,191],{},"Edit Roles",[58,193,194],{},"Can create and modify roles in the organisation.",[43,196,197,202],{},[58,198,199],{},[61,200,201],{},"Manage Joining",[58,203,204,205,209],{},"Can choose which email domains may join the organisation and create shareable invite links. This decides who is ",[206,207,208],"em",{},"able"," to ask, which is why it is separate from Invite Members — approving an individual request needs that permission instead.",[92,211,213],{"id":212},"billing-and-licence-permissions","Billing and Licence Permissions",[37,215,216,224],{},[40,217,218],{},[43,219,220,222],{},[46,221,104],{},[46,223,51],{},[53,225,226,248,258,268],{},[43,227,228,233],{},[58,229,230],{},[61,231,232],{},"View Billing Info",[58,234,235,236,239,240,243,244,247],{},"Can see the organisation's ",[61,237,238],{},"Licenses",", ",[61,241,242],{},"Activity"," and ",[61,245,246],{},"Usage"," tabs — seat counts, holders, the allocation ledger, the activity record and egress usage.",[43,249,250,255],{},[58,251,252],{},[61,253,254],{},"View Billing Invoices",[58,256,257],{},"Can see purchase receipts and invoices, including historic ones.",[43,259,260,265],{},[58,261,262],{},[61,263,264],{},"Assign Licenses",[58,266,267],{},"Can assign the organisation's licence seats to members, and revoke them.",[43,269,270,275],{},[58,271,272],{},[61,273,274],{},"Purchase Licenses",[58,276,277],{},"Can buy additional licence seats for the organisation.",[14,279,280,281,285],{},"See ",[26,282,284],{"href":283},"licensing","Licensing"," for what the tiers and seats are.",[32,287,29],{"id":288},"roles",[14,290,291],{},"Roles are named collections of permissions that can be assigned to members. A member's effective permissions are the union of all their assigned roles plus any individually granted permissions. Permissions are additive — a role cannot revoke a permission granted by another role.",[14,293,294],{},"Roles can optionally be scoped to specific projects, limiting where those permissions apply.",[14,296,280,297,299],{},[26,298,29],{"href":28}," in the Organisations guide for details on creating and managing roles.",[32,301,303],{"id":302},"organisation-default-permissions","Organisation Default Permissions",[14,305,306],{},"Organisations have a set of default permissions that are automatically granted to all members. These can be configured in the Organisation Settings page by an Owner.",[18,308,310],{"id":309},"projects","Projects",[14,312,313],{},"File and scene permissions apply at the project level. A member's access to the contents of a project is determined by the permissions they hold for that project (either directly or through roles scoped to that project).",[92,315,317],{"id":316},"file-permissions","File Permissions",[37,319,320,328],{},[40,321,322],{},[43,323,324,326],{},[46,325,104],{},[46,327,51],{},[53,329,330,340,350,360,370],{},[43,331,332,337],{},[58,333,334],{},[61,335,336],{},"View File List",[58,338,339],{},"Can see the list of files in the project.",[43,341,342,347],{},[58,343,344],{},[61,345,346],{},"Stream Files",[58,348,349],{},"Can stream files from the project into udSDK applications (e.g. udStream), including files referenced in scenes. Streaming is free.",[43,351,352,357],{},[58,353,354],{},[61,355,356],{},"Download Files",[58,358,359],{},"Can download files from the project to local storage. Separate from streaming; organisation owners are charged for downloads.",[43,361,362,367],{},[58,363,364],{},[61,365,366],{},"Manage Files",[58,368,369],{},"Can upload, rename, move and delete files in the project, and create folders.",[43,371,372,377],{},[58,373,374],{},[61,375,376],{},"Configure File Settings",[58,378,379],{},"Can configure file storage settings for the project (e.g. connect an AWS S3 bucket, an Azure Blob container, or a local\u002Fnetwork path).",[14,381,382,383,243,386,30],{},"Two further file permissions exist in the data model but have no feature behind them yet, so they are not offered when editing a role: ",[61,384,385],{},"Archive Files",[61,387,388],{},"Share Files",[92,390,392],{"id":391},"scene-permissions","Scene Permissions",[37,394,395,403],{},[40,396,397],{},[43,398,399,401],{},[46,400,104],{},[46,402,51],{},[53,404,405,415,425,435,445],{},[43,406,407,412],{},[58,408,409],{},[61,410,411],{},"View Scene List",[58,413,414],{},"Can see the list of scenes in the project.",[43,416,417,422],{},[58,418,419],{},[61,420,421],{},"Read Scenes",[58,423,424],{},"Can load scenes in supported applications (e.g. udStream).",[43,426,427,432],{},[58,428,429],{},[61,430,431],{},"Edit Scenes",[58,433,434],{},"Can modify scenes in supported applications (save and collaborate).",[43,436,437,442],{},[58,438,439],{},[61,440,441],{},"Manage Scenes",[58,443,444],{},"Can create, upload, delete and rename scenes.",[43,446,447,452],{},[58,448,449],{},[61,450,451],{},"Share Scenes",[58,453,454,455,30],{},"Can share scenes with other members, and share them for preview so people with no account can open them. Sharing for preview also requires a Studio license; withdrawing it does not. See ",[26,456,458],{"href":457},"scenes#sharing-a-scene-for-preview","Scenes",[14,460,461],{},"Share Scenes is granted to members by default and is enforced by the server, but it is not offered as a tick-box when editing a role.",[92,463,465],{"id":464},"work-item-permissions","Work Item Permissions",[37,467,468,476],{},[40,469,470],{},[43,471,472,474],{},[46,473,104],{},[46,475,51],{},[53,477,478,488,498,508,518,528],{},[43,479,480,485],{},[58,481,482],{},[61,483,484],{},"View Work Items",[58,486,487],{},"Can see the work item list, individual items, their history and comments, and post comments.",[43,489,490,495],{},[58,491,492],{},[61,493,494],{},"Create Work Items",[58,496,497],{},"Can raise new work items.",[43,499,500,505],{},[58,501,502],{},[61,503,504],{},"Edit Work Items",[58,506,507],{},"Can edit work item fields and move items between the everyday states.",[43,509,510,515],{},[58,511,512],{},[61,513,514],{},"Assign Work Items",[58,516,517],{},"Can assign and unassign work items.",[43,519,520,525],{},[58,521,522],{},[61,523,524],{},"Manage Work Items",[58,526,527],{},"Can delete work items, and delete other members' comments.",[43,529,530,535],{},[58,531,532],{},[61,533,534],{},"Resolve Work Items",[58,536,537],{},"Can close items out and record how they ended. Deliberately separate from Edit — deciding something is finished is a different call from working on it.",[14,539,280,540,30],{},[26,541,543],{"href":542},"workitems","Work Items",[92,545,547],{"id":546},"job-permissions","Job Permissions",[14,549,550,243,553,556,557,560],{},[61,551,552],{},"View Job List",[61,554,555],{},"Create Jobs"," exist in the data model, but ",[26,558,559],{"href":559},"jobs"," are not yet managed from the web interface, so these are not offered when editing a role.",[18,562,564],{"id":563},"server-wide-administration","Server Wide Administration",[14,566,567,568,571],{},"Server administrators have access across all organisations and users on the server instance. Opening the Admin console at all requires the ",[61,569,570],{},"Admin"," global permission on the account, and each section within it is gated by a further global permission — user administration, organisation administration, server configuration, analytics, backups and licence issuing are all separately grantable, so an administrator can be given only the areas they need.",[14,573,574,575,579],{},"Global permissions are assigned per user from the Admin console. For the full list and what each one grants, see the administrator guide's ",[26,576,578],{"href":577},"\u002Fdocs\u002Fadmin\u002Fadmin-console#global-permissions","Admin Console"," page. Regular users do not have access to server-wide settings.",{"title":581,"searchDepth":582,"depth":582,"links":583},"",2,[584,591,592],{"id":20,"depth":582,"text":21,"children":585},[586,588,589,590],{"id":34,"depth":587,"text":35},3,{"id":89,"depth":587,"text":90},{"id":288,"depth":587,"text":29},{"id":302,"depth":587,"text":303},{"id":309,"depth":582,"text":310},{"id":563,"depth":582,"text":564},"md",{},true,"\u002Fuser\u002Fpermissions",{"title":5,"description":16},"1.user\u002Fpermissions","y0EIfM4NvZ0u4Gd6eqz_UvdWn7NNqydsZAcb2uqgm-0",[601,605,659,719],{"title":602,"path":603,"stem":604},"udServer Manuals","\u002F","0.index",{"title":606,"path":607,"stem":608,"children":609},"User Guide","\u002Fdocs\u002Fuser","1.user\u002F0.index",[610,614,618,622,626,630,633,636,638,642,646,649,652,656],{"title":611,"path":612,"stem":613},"Login","\u002Fdocs\u002Fuser\u002Flogin","1.user\u002F1.login",{"title":615,"path":616,"stem":617},"Account Settings","\u002Fdocs\u002Fuser\u002Faccount-settings","1.user\u002Faccount-settings",{"title":619,"path":620,"stem":621},"Files","\u002Fdocs\u002Fuser\u002Ffiles","1.user\u002Ffiles",{"title":623,"path":624,"stem":625},"Jobs","\u002Fdocs\u002Fuser\u002Fjobs","1.user\u002Fjobs",{"title":627,"path":628,"stem":629},"3rd Party Licenses","\u002Fdocs\u002Fuser\u002Flicenses","1.user\u002Flicenses",{"title":284,"path":631,"stem":632},"\u002Fdocs\u002Fuser\u002Flicensing","1.user\u002Flicensing",{"title":21,"path":634,"stem":635},"\u002Fdocs\u002Fuser\u002Forganisations","1.user\u002Forganisations",{"title":5,"path":637,"stem":598},"\u002Fdocs\u002Fuser\u002Fpermissions",{"title":639,"path":640,"stem":641},"Connecting an Azure Blob Container to a Project","\u002Fdocs\u002Fuser\u002Fproject-azure-setup","1.user\u002Fproject-azure-setup",{"title":643,"path":644,"stem":645},"Connecting an AWS S3 Bucket to a Project","\u002Fdocs\u002Fuser\u002Fproject-s3-setup","1.user\u002Fproject-s3-setup",{"title":310,"path":647,"stem":648},"\u002Fdocs\u002Fuser\u002Fprojects","1.user\u002Fprojects",{"title":458,"path":650,"stem":651},"\u002Fdocs\u002Fuser\u002Fscenes","1.user\u002Fscenes",{"title":653,"path":654,"stem":655},"Software Downloads","\u002Fdocs\u002Fuser\u002Fsoftware","1.user\u002Fsoftware",{"title":543,"path":657,"stem":658},"\u002Fdocs\u002Fuser\u002Fworkitems","1.user\u002Fworkitems",{"title":660,"path":661,"stem":662,"children":663},"IT Administrators Guide","\u002Fdocs\u002Fadmin","2.admin\u002F0.index",[664,668,672,676,680,684,688,692,696,700,703,707,711,715],{"title":665,"path":666,"stem":667},"System Requirements","\u002Fdocs\u002Fadmin\u002Fsystem-requirements","2.admin\u002F1.system-requirements",{"title":669,"path":670,"stem":671},"Publishing Software (Packages)","\u002Fdocs\u002Fadmin\u002Fsoftware-packages","2.admin\u002F10.software-packages",{"title":673,"path":674,"stem":675},"Legal Documents","\u002Fdocs\u002Fadmin\u002Flegal-documents","2.admin\u002F11.legal-documents",{"title":677,"path":678,"stem":679},"Licensing & Purchasing","\u002Fdocs\u002Fadmin\u002Flicensing","2.admin\u002F12.licensing",{"title":681,"path":682,"stem":683},"Egress","\u002Fdocs\u002Fadmin\u002Fegress","2.admin\u002F13.egress",{"title":685,"path":686,"stem":687},"Backups & Restore","\u002Fdocs\u002Fadmin\u002Fbackups","2.admin\u002F14.backups",{"title":689,"path":690,"stem":691},"Generic Installation","\u002Fdocs\u002Fadmin\u002Fgettingstarted","2.admin\u002F2.gettingstarted",{"title":693,"path":694,"stem":695},"Setting up on an Amazon EC2 instance","\u002Fdocs\u002Fadmin\u002Famazon-ec2","2.admin\u002F3.amazon-ec2",{"title":697,"path":698,"stem":699},"Configuring OAuth \u002F OIDC Authentication","\u002Fdocs\u002Fadmin\u002Foauth","2.admin\u002F4.oauth",{"title":578,"path":701,"stem":702},"\u002Fdocs\u002Fadmin\u002Fadmin-console","2.admin\u002F5.admin-console",{"title":704,"path":705,"stem":706},"Server Configuration","\u002Fdocs\u002Fadmin\u002Fserver-configuration","2.admin\u002F6.server-configuration",{"title":708,"path":709,"stem":710},"Users & Organisations","\u002Fdocs\u002Fadmin\u002Fusers-and-organisations","2.admin\u002F7.users-and-organisations",{"title":712,"path":713,"stem":714},"Analytics & System Log","\u002Fdocs\u002Fadmin\u002Fanalytics-and-logs","2.admin\u002F8.analytics-and-logs",{"title":716,"path":717,"stem":718},"Webhooks","\u002Fdocs\u002Fadmin\u002Fwebhooks","2.admin\u002F9.webhooks",{"title":720,"path":721,"stem":722,"children":723},"Developers Guide","\u002Fdocs\u002Fdev","3.dev\u002F0.index",[724,728],{"title":725,"path":726,"stem":727},"udServer API","\u002Fdocs\u002Fdev\u002Fudserverapi","3.dev\u002FudServerAPI",{"title":729,"path":730,"stem":731},"WebSocket API","\u002Fdocs\u002Fdev\u002Fwebsocketapi","3.dev\u002Fwebsocketapi",[733,735],{"title":21,"path":734,"stem":635,"children":-1},"\u002Fuser\u002Forganisations",{"title":639,"path":736,"stem":641,"children":-1},"\u002Fuser\u002Fproject-azure-setup",1787483254234]