Skip to content

Workspace administration

Workspace administration controls who can see data, which projects and environments exist, and which tokens can read or ingest telemetry.

Use workspace settings for:

  • Workspace rename and delete
  • Members and grants
  • Built-in and custom roles
  • API, ingest, and feature-flag SDK tokens
  • Audit log review

Use project settings for:

  • Project rename and retention settings
  • Environment creation and deletion
  • Environment auto-registration controls
  • Service catalog metadata

Use account settings for the signed-in user:

  • Display name changes
  • Password changes for local-password accounts

OIDC-only accounts do not have an Oriel-managed password to change.

Administration is permission-based. Common grants include:

Area Read Manage
Members members:read members:manage
Roles roles:read roles:manage
Tokens tokens:read tokens:manage
Projects projects:read projects:manage
Environments projects:read environments:manage
Services projects:read services:manage
Feature flags flags:read flags:write
Flag SDK keys tokens:read flags:manage to mint; tokens:manage to revoke
Audit log audit:read Not editable

Grant changes enforce no-escalation: a caller can only grant permissions already held at the target scope.

  • Review audit entries after member, role, token, and workspace changes.
  • Use project retention settings to match telemetry value and storage cost.
  • Use environment caps to prevent unbounded preview environment growth.
  • Keep API tokens, ingest tokens, and feature-flag SDK keys separate.