RBAC Migration Guide
Use this guide to migrate your users to RBAC and understand the changes for your existing users.
Existing Users
Existing users will be given the following roles automatically. You'll need to adjust their user access accordingly.
-
If a user had an Admin role, they are given the role of Org Admin, Project Admin, and Environment Admin.
-
If a user had a non-administrative role, then they are given the role of Org Contributors, Project Admins, and Environment Admin.
Licensing
Any user assigned at least one of the following roles, will count towards your license allocation.
-
Org Admin
-
Project Admin
-
Project Architect
-
Project Contributor
Users who are only assigned the following roles are considered read-only users and will not count against the license allocation. The user can't be assigned any of the above roles.
-
Org Contributor
-
Org Member
-
Project Member
-
Environment Admin
-
Environment Reader
Service Accounts
Service accounts should only be granted from one of the following roles:
If your service account needs to deploy and refresh, assign the Environment Admin role.
-
Org Contributor
-
Org Member
-
Project Member
-
Environment Reader
-
Environment Admin