Skip to content

Workspace Administration

Administer the Oriel workspace without breaking tenancy or escalating grants.

Use workspace settings for:

  • Workspace rename and delete
  • Members and grants
  • Built-in and custom roles
  • API, ingest, and feature-flag SDK tokens
  • Audit log review

Use project settings for:

  • Project rename and retention settings
  • Environment creation and deletion
  • Environment auto-registration controls
  • Service catalog metadata

Administration is permission-based. Common grants include:

AreaReadManage
Membersmembers:readmembers:manage
Rolesroles:readroles:manage
Tokenstokens:readtokens:manage
Projectsprojects:readprojects:manage
Environmentsprojects:readenvironments:manage
Servicesprojects:readservices:manage
Feature flagsflags:readflags:write
Flag SDK keystokens:readflags:manage to mint; tokens:manage to revoke
Audit logaudit:readNot editable

Grant changes enforce no-escalation: a caller can only grant permissions already held at the target scope.

  • Review audit entries after member, role, token, and workspace changes.
  • Use project retention settings to match telemetry value and storage cost.
  • Use environment caps to prevent unbounded preview environment growth.
  • Keep API tokens, ingest tokens, and feature-flag SDK keys separate.