Documentation
Who can do what
[object Object]
In CloseYourIt what a person sees and does is built from a few pieces that add up. This page explains the pieces and where to change them. All the pages are under Administration.
The pieces
- Permission: a single action, for example "Delete tickets".
- Role: a named set of permissions, for example "Maintainer". Changing a role updates everyone who has it right away.
- Team: a group of people, with its roles and the projects they apply to.
- Scope: the groups and projects a person sees. Giving a group means giving all its projects, including those still to come.
If a piece is missing, the action does not go through. A project permission without visible projects does nothing.
Seeing and doing
Whoever sees a project reads its tickets, errors, logs and measurements. They can also open tickets, comment on them, ask questions, propose and vote on ideas. None of this needs a permission.
Permissions are for the rest: editing and assigning tickets, sorting errors, deleting. Each permission applies in one of two ways:
- project: only on the projects the person sees;
- org: on the whole organization. It cannot be narrowed to a project.
Some permissions are marked sensitive: they destroy data, open confidential values, run commands on machines or let someone give themselves more permissions. Actions going through them always ask for a confirmation: in the browser a question, in the terminal the command repeated with --yes. Each confirmation is recorded, with who gave it and when.
People's levels
On the Members page the Level column says how a person belongs to the organization:
| Level | What it means |
|---|---|
| Owner | sees every project and can do everything. There is only one per organization. |
| Admin, Member | see the projects in their scope and do what their roles grant. |
| Customer | an external person. Sees the projects in their scope, but the menu hides the technical areas where there is nothing for them. Of the questions on tickets, they only see those marked Visible to the client too. |
The level is not the list of permissions: that comes from roles.
Ready-made roles
Each organization starts with four roles, which you can change:
- Viewer: nothing beyond reading;
- Triager: sorts errors, vulnerabilities and SEO issues, assigns errors and turns them into tickets;
- Maintainer: manages tickets, ideas, knowledge, tokens, secrets and the other resources of the projects;
- Administrator: every permission.
To see what a role grants, open Roles and click the role. To change it use Edit role; to create one, New role. You need the "Manage roles & permissions" permission.
Give access with a team
It is the easiest way when several people do the same work.
- Open Teams and press New team.
- In Roles pick one or more roles.
- In Scope · Groups and Scope · Projects pick where they apply.
- In Members add the people.
Whoever joins the team gets its roles and scope right away. A team can also have a Default ticket assignee.
cyi teams create Support --role Triager --group Acme
cyi teams add-member Support [email protected]
Give access to a single person
- Open Members, then Manage access on the person's row.
- In the Access tab pick the Groups and Projects they see, on top of their teams' ones, and the Direct roles.
- In the Exceptions tab you can allow or deny a single permission. A personal exception wins over roles.
- The Effective permissions tab shows the result and where each permission comes from.
Managing access needs the "Manage members & access" permission.
Limit secrets to some environments
In a person's Access tab, Secret environments decides on which environments they can see and change secrets: for example staging yes, production no. Empty means no limit. On a single project you can make an exception, which wins over the general rule. See Secrets.
Invite a person
- In Members press Invite member.
- Write the email and pick the Role: Member, Admin or Customer.
- Press Send invitation.
Once the person has accepted, give them a scope and roles, directly or through a team. You need the "Invite members" permission.
Remove on a member takes away all their access at once: projects, roles, teams and command-line keys. Their account stays.
Service accounts for agents and scripts
A service account is a member that is not a person: it does not sign in from the browser, it only uses command-line tokens. It is for an AI agent or a script that needs to read secrets or work on tickets.
- Open Service accounts and press New service account.
- Pick Visible projects and Visible groups: it will see only those.
- If needed, assign Roles and tick Read + write secrets.
- In Allowed environments (secrets) limit the environments, for example no production.
- Create a token from its page and copy it right away: it is shown only once.
A service account cannot sign the approval of a review: a person always gives that.
cyi service-accounts create --name "Deploy bot" --project acme-api --grant-secrets --secret-environment staging
You need the "Manage members & access" permission. Deleting a service account stops its tokens from working at once.