ZITADEL Docs
Configure Identity & PoliciesRoles & Permissions

ZITADEL Administrators

Terminology Update: We have streamlined our naming conventions to improve clarity. The term Administrators now replaces what was previously referred to as Members, Memberships or Managers. These terms all refer to the same underlying functionality.

Administrators are users or service accounts who have permission to manage resources within ZITADEL.

Administrator permissions can be assigned to different levels in ZITADEL:

  • IAM Administrators: This is the highest level. Users with IAM Administrator roles are able to manage the whole Instance.
  • Organization Administrators: Administrators at the Organization level are able to view or manage everything, according to their permissions, within the granted Organization.
  • Project Administrators: In this level the user is able to manage a project.
  • Project Grant Administrators: The project grant administrator manages projects granted by another organization.

The scope of the administrators is restricted based on their level. Which means that an administrator, assigned to one organization, will have access only to the resources and settings of that organization. Only the Administrators on the instance level can view resources, such as users, across all organizations.

To configure administrators in ZITADEL, go to the resource where you like to add it (e.g., Instance, Organization, Project, GrantedProject). In the right part of the management console you can find ADMINISTRATORS in the details part. Here you have a list of the current administrators and can add a new one.

Administrators

When adding a new administrator, you can select multiple roles, some of which are only allowed to read data. This can be especially useful if you add service account for one of your projects where you only need read access.

By default, you will only search for users within the selected organization. If you like to give a role to a user outside the organization, you need to switch to the global search and type the exact loginname of the users. This will prevent users from guessing users from other organizations.

Administrators

Roles

NameRoleDescription
Instance OwnerIAM_OWNERManage the Instance, manage all organizations with their content
Instance Owner ViewerIAM_OWNER_VIEWERView the Instance and view all organizations with their content
Instance Org ManagerIAM_ORG_MANAGERManage all organizations including their policies, projects and users
Instance User ManagerIAM_USER_MANAGERManage all users and their authorizations over all organizations
Instance Admin ImpersonatorIAM_ADMIN_IMPERSONATORAllow impersonation of admin and end users from all organizations
Instance ImpersonatorIAM_END_USER_IMPERSONATORAllow impersonation of end users from all organizations
Instance Login ClientIAM_LOGIN_CLIENTGet all permissions needed to implement your own Login UI.
Org OwnerORG_OWNERManage everything within an organization
Org Owner ViewerORG_OWNER_VIEWERView everything within an organization
Org User ManagerORG_USER_MANAGERManage users and their authorizations within an organization
Org User Permission EditorORG_USER_PERMISSION_EDITORManage user grants and view everything needed for this
Org Project Permission EditorORG_PROJECT_PERMISSION_EDITORGrant Projects to other organizations and view everything needed for this
Org Project CreatorORG_PROJECT_CREATORThis role is used for users in the global organization. They are allowed to create projects and manage them.
Org Dynamic Client RegistrarORG_DYNAMIC_CLIENT_REGISTRARRegister OAuth 2.0 clients through the dynamic client registration endpoint, and nothing else
Org Admin ImpersonatorORG_ADMIN_IMPERSONATORAllow impersonation of admin and end users from the organization
Org ImpersonatorORG_END_USER_IMPERSONATORAllow impersonation of end users from the organization
Project OwnerPROJECT_OWNERManage everything within a project. This includes to grant users for the project.
Project Owner ViewerPROJECT_OWNER_VIEWERView everything within a project.
Project Owner GlobalPROJECT_OWNER_GLOBALSame as PROJECT_OWNER, but in the global organization.
Project Owner Viewer GlobalPROJECT_OWNER_VIEWER_GLOBALSame as PROJECT_OWNER_VIEWER, but in the global organization.
Project Grant OwnerPROJECT_GRANT_OWNERSame as PROJECT_OWNER but for a granted project.
Org User Self ManagerORG_USER_SELF_MANAGERGrants a user permission to read policies and delete their own account.
Self Management GlobalSELF_MANAGEMENT_GLOBALGrants a user permission to create organizations, read policies, and delete their own account, in the global organization.

Configure roles

If you run a self-hosted ZITADEL instance, you can define your custom roles by overwriting the defaults.yaml In the InternalAuthZ section you will find all the roles and which permissions they have.

Example:

InternalAuthZ:
  RolePermissionMappings:
    - Role: "IAM_OWNER"
      Permissions:
        - "iam.read"
        - "iam.write"

Administrator Permission Matrix

This table is generated dynamically from our settings file.

PermissionIAM ADMIN IMPERSONATORIAM END USER IMPERSONATORIAM LOGIN CLIENTIAM ORG MANAGERIAM OWNERIAM OWNER VIEWERIAM USER MANAGERORG ADMIN IMPERSONATORORG DYNAMIC CLIENT REGISTRARORG END USER IMPERSONATORORG OWNERORG OWNER VIEWERORG PROJECT CREATORORG PROJECT PERMISSION EDITORORG SETTINGS MANAGERORG USER MANAGERORG USER PERMISSION EDITORORG USER SELF MANAGERPROJECT GRANT OWNERPROJECT GRANT OWNER VIEWERPROJECT OWNERPROJECT OWNER GLOBALPROJECT OWNER VIEWERPROJECT OWNER VIEWER GLOBALSELF MANAGEMENT GLOBALSYSTEM OWNERSYSTEM OWNER VIEWER
action.execution.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
action.execution.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
action.target.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
action.target.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
action.target.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
admin.impersonationNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
events.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
group.createNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
group.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
group.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
group.user.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
group.user.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
group.user.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
group.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.action.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.action.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.action.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.debug.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.debug.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.feature.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.feature.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.feature.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.flow.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.flow.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.flow.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.idp.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.idp.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.idp.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.member.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.member.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.member.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.policy.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.policy.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.policy.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.restrictions.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.restrictions.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.web_key.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.web_key.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.web_key.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
iam.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
impersonationNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
milestones.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.action.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.action.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.action.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.createNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.feature.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.feature.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.feature.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.flow.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.flow.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.flow.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.global.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.idp.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.idp.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.idp.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.member.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.member.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.member.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
org.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
policy.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
policy.readNoNoNoNoNoNoNoNo
policy.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.app.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.app.readNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.app.register_dynamicNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.app.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.createNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.grant.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.grant.member.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.grant.member.readNoNoNoNoNoNoNoNoNoNoNoNoNo
project.grant.member.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.grant.readNoNoNoNoNoNoNoNoNoNoNoNoNo
project.grant.user.grant.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.grant.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.member.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.member.readNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.member.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.readNoNoNoNoNoNoNoNoNoNoNo
project.read:selfNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.role.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.role.readNoNoNoNoNoNoNoNoNoNoNoNoNo
project.role.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
project.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
session.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
session.linkNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
session.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
session.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.debug.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.debug.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.debug.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.domain.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.domain.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.domain.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.feature.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.feature.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.feature.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.iam.member.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.instance.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.instance.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.instance.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.limits.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.limits.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.quota.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
system.quota.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.credential.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.feature.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.feature.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.feature.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.global.readNoNoNoNoNoNoNoNoNoNoNo
user.grant.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.grant.readNoNoNoNoNoNoNoNoNoNoNo
user.grant.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.membership.readNoNoNoNoNoNoNoNoNoNoNoNoNo
user.passkey.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.readNoNoNoNoNoNoNoNoNoNoNoNoNo
user.self.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
user.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
userschema.deleteNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
userschema.readNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo
userschema.writeNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNoNo

Was this page helpful?

On this page