[{"data":1,"prerenderedAt":830},["ShallowReactive",2],{"docs-pages-en":3,"doc-en-permissions":308},[4,9,15,20,25,30,35,41,52,60,69,77,84,92,96,105,109,117,122,127,132,138,143,148,153,158,163,169,174,179,184,189,194,199,204,209,214,219,224,229,234,239,244,249,254,260,265,269,273,278,283,288,293,298,303],{"path":5,"title":6,"description":7,"order":8,"group":8,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fpermissions","Who can do what","[object Object]",null,{"path":10,"title":11,"description":12,"order":13,"group":14,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Finstallation","Installation","Install CloseYourIt on your own server with one command.",1,"start",{"path":16,"title":17,"description":18,"order":19,"group":14,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fsettings","Settings","Every setting in the .env file, what it does and which ones you must never change.",2,{"path":21,"title":22,"description":23,"order":24,"group":14,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fdatabase","Database","What the database is, what is inside, how long data stays and how much room it takes.",3,{"path":26,"title":27,"description":28,"order":29,"group":14,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fupdates-and-backups","Updates and backups","Update to a new version, back up and restore the database, check the install.",4,{"path":31,"title":32,"description":33,"order":34,"group":14,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Ftroubleshooting","Troubleshooting","What to check when the install, the certificate, email or incoming data do not work.",5,{"path":36,"title":37,"description":38,"order":39,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fconnect-your-apps","Connect your apps","Every tool that sends data to CloseYourIt, and what each one collects.",6,"connect",{"path":42,"title":43,"description":44,"order":45,"group":8,"parent":46,"package":47,"note":48,"collects":49,"status":8},"\u002Fdocs\u002Fsdk-ruby","Ruby \u002F Rails","The closeyourit-ruby gem sends errors, logs, slow queries and job metrics from a Rails app.",7,"connect-your-apps","closeyourit-ruby","Errors, logs, slow queries and methods, background jobs.",{"errors":50,"logs":50,"performance":50,"visits":51,"servers":51},"full","none",{"path":53,"title":54,"description":55,"order":56,"group":8,"parent":46,"package":57,"note":58,"collects":59,"status":8},"\u002Fdocs\u002Fsdk-javascript","JavaScript","The @bussolabs\u002Fcloseyourit-js package works in the browser and on Node 20.16 or newer.",8,"@bussolabs\u002Fcloseyourit-js","Browser and Node, framework adapters and database queries from 0.13.0.",{"errors":50,"logs":50,"performance":50,"visits":50,"servers":51},{"path":61,"title":62,"description":63,"order":64,"group":8,"parent":46,"package":65,"note":66,"collects":67,"status":8},"\u002Fdocs\u002Fsdk-dart","Dart \u002F Flutter","The closeyourit package captures the errors of Flutter apps, even when the phone is offline.",9,"closeyourit","Public errors, logs and metrics from 0.9.3.",{"errors":50,"logs":68,"performance":68,"visits":51,"servers":51},"partial",{"path":70,"title":71,"description":72,"order":73,"group":8,"parent":46,"package":65,"note":74,"collects":75,"status":76},"\u002Fdocs\u002Fsdk-python","Python","The closeyourit package sends errors, logs and metrics from server-side Python applications.",10,"Server side. SQLAlchemy; Django query monitoring and FastAPI\u002FStarlette from 0.4.0.",{"errors":50,"logs":50,"performance":68,"visits":51,"servers":51},"pre_alpha",{"path":78,"title":79,"description":80,"order":81,"group":8,"parent":46,"package":79,"note":82,"collects":83,"status":8},"\u002Fdocs\u002Fsdk-sentry","Sentry SDK","Send errors with a compatible Sentry SDK; sessions and crashes have separate profiles.",11,"Compatible errors; sessions and crashes require a verified profile.",{"errors":50,"logs":51,"performance":51,"visits":51,"servers":51},{"path":85,"title":86,"description":87,"order":88,"group":8,"parent":46,"package":89,"note":90,"collects":91,"status":8},"\u002Fdocs\u002Fagent-server","Server agent","A small program on the server that sends the state of the machine every 60 seconds.",12,"closeyourit-agent","CPU, memory, disks, network, containers and services.",{"errors":51,"logs":68,"performance":51,"visits":51,"servers":50},{"path":93,"title":94,"description":95,"order":88,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fnuxt","Vue and Nuxt","Connect Nuxt browser errors and Nitro server errors without exposing a server token.",{"path":97,"title":98,"description":99,"order":100,"group":8,"parent":46,"package":101,"note":102,"collects":103,"status":104},"\u002Fdocs\u002Fagent-kubernetes","Kubernetes","A read-only observer of the cluster: one copy per cluster.",13,"closeyourit-kube","Machines, apps and error events of the cluster.",{"errors":51,"logs":51,"performance":51,"visits":51,"servers":50},"coming",{"path":106,"title":107,"description":108,"order":100,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fopentelemetry","OpenTelemetry","Send server traces, metrics and logs through the optional OTLP receiver.",{"path":110,"title":111,"description":112,"order":113,"group":8,"parent":46,"package":114,"note":115,"collects":116,"status":8},"\u002Fdocs\u002Fcli","cyi CLI","The closeyourit command, cyi for short: manage projects, errors and tickets from the terminal.",14,"@bussolabs\u002Fcloseyourit-cli","It collects no data: it drives CloseYourIt from the terminal.",{"errors":51,"logs":51,"performance":51,"visits":51,"servers":51},{"path":118,"title":119,"description":120,"order":121,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fhttp-api","HTTP API","Send errors, logs, metrics and page views with plain HTTP requests, without an SDK.",15,{"path":123,"title":124,"description":125,"order":126,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fgithub-app","GitHub","Connect GitHub repositories to tickets and releases with your own GitHub App.",16,{"path":128,"title":129,"description":130,"order":131,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fingest-gateway","Ingest gateway","Keep incoming errors, logs and metrics safe when the app is slow or restarting.",17,{"path":133,"title":134,"description":135,"order":136,"group":137,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fai","AI","Turn on assistant, analysis, dictation and smart search with a CloseYourIt AI key or your own provider.",18,"automation",{"path":139,"title":140,"description":141,"order":142,"group":137,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fautomator","Automator","Let tickets be worked automatically on your own Linux machine, with Claude Code, Codex or both.",19,{"path":144,"title":145,"description":146,"order":147,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fstack-coverage","Frameworks and stack coverage","Choose a published SDK or understand the limits of a locally tested integration.",20,{"path":149,"title":150,"description":151,"order":152,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fmonitoring","Traces, measurements and sessions","Explore the new signals, compare releases and recover original error locations.",21,{"path":154,"title":155,"description":156,"order":157,"group":40,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fnode-database","Node databases","Monitor slow and repeated queries with pg, mysql2, Drizzle and Prisma PostgreSQL.",22,{"path":159,"title":160,"description":161,"order":162,"group":137,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fclaude-code","Claude Code","CloseYourIt inside Claude Code, in a column next to the conversation with production and your open tickets.",23,{"path":164,"title":165,"description":166,"order":167,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Ftickets","Tickets and ideas","Open and follow tickets on the board, group them into milestones, ask questions and turn voted ideas into work.",30,"use",{"path":170,"title":171,"description":172,"order":173,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Ferrors","Errors","How your apps' errors become single rows, and how to resolve, ignore, merge or turn them into tickets.",31,{"path":175,"title":176,"description":177,"order":178,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fperformance","Performance","Find slow queries and methods, read the problems detected automatically and get an alert when one appears.",32,{"path":180,"title":181,"description":182,"order":183,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Flogs","Logs","Search your apps' messages, follow a request from start to end and link a message to an error or a ticket.",33,{"path":185,"title":186,"description":187,"order":188,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fsecrets","Secrets","Passwords, keys and private files in one place, per project and environment, read by your app without a .env on disk.",34,{"path":190,"title":191,"description":192,"order":193,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fservers","Servers","The state of your machines on one page, with history and alerts when something breaks or fills up.",35,{"path":195,"title":196,"description":197,"order":198,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fuptime","Uptime","Check that your sites answer, keep count of outages and show them to customers on a status page.",36,{"path":200,"title":201,"description":202,"order":203,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fcrons","Scheduled jobs","Notice when a job that should run on its own stops running, or runs and ends badly.",37,{"path":205,"title":206,"description":207,"order":208,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Falerts","Alerts","The rules that create an alert, the notification center and where each person chooses to receive them.",38,{"path":210,"title":211,"description":212,"order":213,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fhelpdesk","Help desk","Visitors of a project's site write to the team with the \"Need help?\" button, and the request lands in the right project.",39,{"path":215,"title":216,"description":217,"order":218,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fanalytics","Site analytics","How many people visit the site, what they look at and where they come from, without cookies.",40,{"path":220,"title":221,"description":222,"order":223,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Freplays","Session replay","Record how people move through the site and watch it back like a video, even next to an error.",41,{"path":225,"title":226,"description":227,"order":228,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Freleases","Releases","The versions running in each environment, bound to GitHub tags, and the errors that come back after a fix.",42,{"path":230,"title":231,"description":232,"order":233,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fvulnerabilities","Vulnerabilities","Known security problems in your projects' libraries, and the languages that no longer get fixes.",43,{"path":235,"title":236,"description":237,"order":238,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fseo","SEO","CloseYourIt visits your sites like a search engine and tells you what keeps your pages from being found.",44,{"path":240,"title":241,"description":242,"order":243,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fknowledge","Knowledge base","Write notes, decisions and guides for your projects, find them by meaning and ask questions with sources.",45,{"path":245,"title":246,"description":247,"order":248,"group":168,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fagents","AI agents","Which tickets agents take, what they hand you, where you decide and how each machine is measured.",46,{"path":250,"title":251,"description":252,"order":253,"group":14,"parent":8,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog","Versions","Every CloseYourIt system with its latest version, and the notes of each release.",50,{"path":255,"title":256,"description":257,"order":258,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-app","App","Every stable version of App, newest first.",51,"changelog",{"path":261,"title":262,"description":263,"order":264,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-cli","Command line (cyi)","Every stable version of Command line (cyi), newest first.",52,{"path":266,"title":140,"description":267,"order":268,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-automator","Every stable version of Automator, newest first.",53,{"path":270,"title":86,"description":271,"order":272,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-agent-server","Every stable version of Server agent, newest first.",54,{"path":274,"title":275,"description":276,"order":277,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-agent-kubernetes","Kubernetes agent","Every stable version of Kubernetes agent, newest first.",55,{"path":279,"title":280,"description":281,"order":282,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-sdk-javascript","JavaScript SDK","Every stable version of JavaScript SDK, newest first.",56,{"path":284,"title":285,"description":286,"order":287,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-sdk-ruby","Ruby SDK","Every stable version of Ruby SDK, newest first.",57,{"path":289,"title":290,"description":291,"order":292,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-sdk-python","Python SDK","Every stable version of Python SDK, newest first.",58,{"path":294,"title":295,"description":296,"order":297,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-sdk-dart","Dart SDK","Every stable version of Dart SDK, newest first.",59,{"path":299,"title":300,"description":301,"order":302,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-skills","Skills for AI assistants","Every stable version of Skills for AI assistants, newest first.",60,{"path":304,"title":305,"description":306,"order":307,"group":8,"parent":259,"package":8,"note":8,"collects":8,"status":8},"\u002Fdocs\u002Fchangelog-site","Website and docs","Every stable version of Website and docs, newest first.",61,{"id":309,"title":6,"body":310,"collects":8,"description":7,"extension":821,"group":8,"meta":822,"navigation":823,"note":8,"order":8,"package":8,"parent":8,"path":5,"seo":824,"status":8,"stem":828,"__hash__":829},"docs_en\u002Fdocs\u002Fpermissions.md",{"type":311,"value":312,"toc":810},"minimark",[313,322,327,355,358,362,365,368,382,394,398,409,465,468,472,475,501,516,520,523,557,563,617,621,662,665,669,682,686,708,711,720,724,727,765,768,803,806],[314,315,316,317,321],"p",{},"In CloseYourIt what a person sees and does is built from a few pieces that add up. This page explains the pieces and where to change them. All the pages are under ",[318,319,320],"strong",{},"Administration",".",[323,324,326],"h2",{"id":325},"the-pieces","The pieces",[328,329,330,337,343,349],"ul",{},[331,332,333,336],"li",{},[318,334,335],{},"Permission",": a single action, for example \"Delete tickets\".",[331,338,339,342],{},[318,340,341],{},"Role",": a named set of permissions, for example \"Maintainer\". Changing a role updates everyone who has it right away.",[331,344,345,348],{},[318,346,347],{},"Team",": a group of people, with its roles and the projects they apply to.",[331,350,351,354],{},[318,352,353],{},"Scope",": the groups and projects a person sees. Giving a group means giving all its projects, including those still to come.",[314,356,357],{},"If a piece is missing, the action does not go through. A project permission without visible projects does nothing.",[323,359,361],{"id":360},"seeing-and-doing","Seeing and doing",[314,363,364],{},"Whoever sees a project reads its tickets, errors, logs and measurements. They can also open tickets, comment on them, ask questions, propose and vote on ideas. None of this needs a permission.",[314,366,367],{},"Permissions are for the rest: editing and assigning tickets, sorting errors, deleting. Each permission applies in one of two ways:",[328,369,370,376],{},[331,371,372,375],{},[318,373,374],{},"project",": only on the projects the person sees;",[331,377,378,381],{},[318,379,380],{},"org",": on the whole organization. It cannot be narrowed to a project.",[314,383,384,385,388,389,393],{},"Some permissions are marked ",[318,386,387],{},"sensitive",": they destroy data, open confidential values, run commands on machines or let someone give themselves more permissions. Actions going through them always ask for a confirmation: in the browser a question, in the terminal the command repeated with ",[390,391,392],"code",{},"--yes",". Each confirmation is recorded, with who gave it and when.",[323,395,397],{"id":396},"peoples-levels","People's levels",[314,399,400,401,404,405,408],{},"On the ",[318,402,403],{},"Members"," page the ",[318,406,407],{},"Level"," column says how a person belongs to the organization:",[410,411,412,424],"table",{},[413,414,415],"thead",{},[416,417,418,421],"tr",{},[419,420,407],"th",{},[419,422,423],{},"What it means",[425,426,427,438,452],"tbody",{},[416,428,429,435],{},[430,431,432],"td",{},[318,433,434],{},"Owner",[430,436,437],{},"sees every project and can do everything. There is only one per organization.",[416,439,440,449],{},[430,441,442,445,446],{},[318,443,444],{},"Admin",", ",[318,447,448],{},"Member",[430,450,451],{},"see the projects in their scope and do what their roles grant.",[416,453,454,459],{},[430,455,456],{},[318,457,458],{},"Customer",[430,460,461,462,321],{},"an external person. Sees the projects in their scope, but the menu hides the technical areas where there is nothing for them. Of the questions on tickets, they only see those marked ",[318,463,464],{},"Visible to the client too",[314,466,467],{},"The level is not the list of permissions: that comes from roles.",[323,469,471],{"id":470},"ready-made-roles","Ready-made roles",[314,473,474],{},"Each organization starts with four roles, which you can change:",[328,476,477,483,489,495],{},[331,478,479,482],{},[318,480,481],{},"Viewer",": nothing beyond reading;",[331,484,485,488],{},[318,486,487],{},"Triager",": sorts errors, vulnerabilities and SEO issues, assigns errors and turns them into tickets;",[331,490,491,494],{},[318,492,493],{},"Maintainer",": manages tickets, ideas, knowledge, tokens, secrets and the other resources of the projects;",[331,496,497,500],{},[318,498,499],{},"Administrator",": every permission.",[314,502,503,504,507,508,511,512,515],{},"To see what a role grants, open ",[318,505,506],{},"Roles"," and click the role. To change it use ",[318,509,510],{},"Edit role","; to create one, ",[318,513,514],{},"New role",". You need the \"Manage roles & permissions\" permission.",[323,517,519],{"id":518},"give-access-with-a-team","Give access with a team",[314,521,522],{},"It is the easiest way when several people do the same work.",[524,525,526,536,542,552],"ol",{},[331,527,528,529,532,533,321],{},"Open ",[318,530,531],{},"Teams"," and press ",[318,534,535],{},"New team",[331,537,538,539,541],{},"In ",[318,540,506],{}," pick one or more roles.",[331,543,538,544,547,548,551],{},[318,545,546],{},"Scope · Groups"," and ",[318,549,550],{},"Scope · Projects"," pick where they apply.",[331,553,538,554,556],{},[318,555,403],{}," add the people.",[314,558,559,560,321],{},"Whoever joins the team gets its roles and scope right away. A team can also have a ",[318,561,562],{},"Default ticket assignee",[564,565,570],"pre",{"className":566,"code":567,"language":568,"meta":569,"style":569},"language-bash shiki shiki-themes github-light github-dark","cyi teams create Support --role Triager --group Acme\ncyi teams add-member Support anna@example.com\n","bash","",[390,571,572,603],{"__ignoreMap":569},[573,574,576,580,584,587,590,594,597,600],"span",{"class":575,"line":13},"line",[573,577,579],{"class":578},"sScJk","cyi",[573,581,583],{"class":582},"sZZnC"," teams",[573,585,586],{"class":582}," create",[573,588,589],{"class":582}," Support",[573,591,593],{"class":592},"sj4cs"," --role",[573,595,596],{"class":582}," Triager",[573,598,599],{"class":592}," --group",[573,601,602],{"class":582}," Acme\n",[573,604,605,607,609,612,614],{"class":575,"line":19},[573,606,579],{"class":578},[573,608,583],{"class":582},[573,610,611],{"class":582}," add-member",[573,613,589],{"class":582},[573,615,616],{"class":582}," anna@example.com\n",[323,618,620],{"id":619},"give-access-to-a-single-person","Give access to a single person",[524,622,623,632,649,655],{},[331,624,528,625,627,628,631],{},[318,626,403],{},", then ",[318,629,630],{},"Manage access"," on the person's row.",[331,633,634,635,638,639,547,642,645,646,321],{},"In the ",[318,636,637],{},"Access"," tab pick the ",[318,640,641],{},"Groups",[318,643,644],{},"Projects"," they see, on top of their teams' ones, and the ",[318,647,648],{},"Direct roles",[331,650,634,651,654],{},[318,652,653],{},"Exceptions"," tab you can allow or deny a single permission. A personal exception wins over roles.",[331,656,657,658,661],{},"The ",[318,659,660],{},"Effective permissions"," tab shows the result and where each permission comes from.",[314,663,664],{},"Managing access needs the \"Manage members & access\" permission.",[323,666,668],{"id":667},"limit-secrets-to-some-environments","Limit secrets to some environments",[314,670,671,672,674,675,678,679,321],{},"In a person's ",[318,673,637],{}," tab, ",[318,676,677],{},"Secret environments"," decides on which environments they can see and change secrets: for example staging yes, production no. Empty means no limit. On a single project you can make an exception, which wins over the general rule. See ",[680,681,186],"a",{"href":185},[323,683,685],{"id":684},"invite-a-person","Invite a person",[524,687,688,696,702],{},[331,689,538,690,692,693,321],{},[318,691,403],{}," press ",[318,694,695],{},"Invite member",[331,697,698,699,701],{},"Write the email and pick the ",[318,700,341],{},": Member, Admin or Customer.",[331,703,704,705,321],{},"Press ",[318,706,707],{},"Send invitation",[314,709,710],{},"Once the person has accepted, give them a scope and roles, directly or through a team. You need the \"Invite members\" permission.",[712,713,714],"warning",{},[314,715,716,719],{},[318,717,718],{},"Remove"," on a member takes away all their access at once: projects, roles, teams and command-line keys. Their account stays.",[323,721,723],{"id":722},"service-accounts-for-agents-and-scripts","Service accounts for agents and scripts",[314,725,726],{},"A service account is a member that is not a person: it does not sign in from the browser, it only uses command-line tokens. It is for an AI agent or a script that needs to read secrets or work on tickets.",[524,728,729,737,747,756,762],{},[331,730,528,731,532,734,321],{},[318,732,733],{},"Service accounts",[318,735,736],{},"New service account",[331,738,739,740,547,743,746],{},"Pick ",[318,741,742],{},"Visible projects",[318,744,745],{},"Visible groups",": it will see only those.",[331,748,749,750,752,753,321],{},"If needed, assign ",[318,751,506],{}," and tick ",[318,754,755],{},"Read + write secrets",[331,757,538,758,761],{},[318,759,760],{},"Allowed environments (secrets)"," limit the environments, for example no production.",[331,763,764],{},"Create a token from its page and copy it right away: it is shown only once.",[314,766,767],{},"A service account cannot sign the approval of a review: a person always gives that.",[564,769,771],{"className":566,"code":770,"language":568,"meta":569,"style":569},"cyi service-accounts create --name \"Deploy bot\" --project acme-api --grant-secrets --secret-environment staging\n",[390,772,773],{"__ignoreMap":569},[573,774,775,777,780,782,785,788,791,794,797,800],{"class":575,"line":13},[573,776,579],{"class":578},[573,778,779],{"class":582}," service-accounts",[573,781,586],{"class":582},[573,783,784],{"class":592}," --name",[573,786,787],{"class":582}," \"Deploy bot\"",[573,789,790],{"class":592}," --project",[573,792,793],{"class":582}," acme-api",[573,795,796],{"class":592}," --grant-secrets",[573,798,799],{"class":592}," --secret-environment",[573,801,802],{"class":582}," staging\n",[314,804,805],{},"You need the \"Manage members & access\" permission. Deleting a service account stops its tokens from working at once.",[807,808,809],"style",{},"html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":569,"searchDepth":19,"depth":19,"links":811},[812,813,814,815,816,817,818,819,820],{"id":325,"depth":19,"text":326},{"id":360,"depth":19,"text":361},{"id":396,"depth":19,"text":397},{"id":470,"depth":19,"text":471},{"id":518,"depth":19,"text":519},{"id":619,"depth":19,"text":620},{"id":667,"depth":19,"text":668},{"id":684,"depth":19,"text":685},{"id":722,"depth":19,"text":723},"md",{},true,{"title":6,"description":825},{"Roles, teams, visible projects and personal exceptions":826,"order":827,"group":168},"how CloseYourIt decides what each person sees and does.",47,"docs\u002Fpermissions","01eHvvb8S4pHwvOgErQP6yMpKLB8Z_Hq4tG55IxGluY",1791469659390]