RBAC Migration Guide

Use this guide to migrate your users to RBAC and understand the changes for your existing users.

Existing Users

Existing users will be given the following roles automatically. You'll need to adjust their user access accordingly.

  • If a user had an Admin role, they are given the role of Org Admin, Project Admin, and Environment Admin.

  • If a user had a non-administrative role, then they are given the role of Org Contributors, Project Admins, and Environment Admin.

Licensing

Any user assigned at least one of the following roles, will count towards your license allocation.

  • Org Admin

  • Project Admin

  • Project Architect

  • Project Contributor

Users who are only assigned the following roles are considered read-only users and will not count against the license allocation. The user can't be assigned any of the above roles.

  • Org Contributor

  • Org Member

  • Project Member

  • Environment Admin

  • Environment Reader

Service Accounts

Service accounts should only be granted from one of the following roles:

If your service account needs to deploy and refresh, assign the Environment Admin role.

  • Org Contributor

  • Org Member

  • Project Member

  • Environment Reader

  • Environment Admin


What’s Next

Learn how to set permissions in Coalesce