Manage users and roles
Camunda Hub controls access to the workspaces, projects, and clusters of your organization through users and roles. Organization admins assign roles and manage users to decide who can use these resources.
Users
Users access Camunda Hub with an organization-level role, and organization admins decide which users can see and change the workspaces, projects, environments, and clusters of the organization. Where you manage users depends on your deployment:
- SaaS
- Self-Managed
You invite and manage users and groups in Camunda Hub, on the Organization > Manage organization page. The Organization Owner has all rights in the organization.
- Create and manage users
- Manage user groups
- Manage resource-based authorizations (legacy, for clusters before version 8.8)
- Organization ownership
You create users in your identity provider, and manage users, groups, and roles in Management Identity.
Access to the Orchestration Cluster applications (Zeebe, Operate, and Tasklist) is managed in Admin, not by the organization role.
The following sections describe the roles and permissions of users in your organization.
Roles and permissions
Every user holds one organization-level role. The following table shows what each role can do.
| Role | Organization | Workspaces and projects | Clusters | Environments | Catalog | Optimize and business value |
|---|---|---|---|---|---|---|
| Organization Owner (SaaS only) | Full access | Manage | Manage | Manage | Manage | Yes |
| Organization Admin | Manage | Manage | Manage | Manage | Manage | Yes |
| DevOps | None | Create and collaborate | Manage | Manage | Read-only | No |
| Analyst | Read-only | Create and collaborate | None | Assigned only | Manage | Yes |
| Member | Read-only | Create and collaborate | None | Assigned only | Read-only | No |
- Organization Owner (SaaS only): All rights in the organization, including settings, billing, and ownership transfer. Reserved for a single user per organization; transferred rather than assigned or removed like other roles.
- Organization Admin: Manages the organization, its members, and its workspaces, with full access to every workspace and project by default. No separate mode needs to be enabled.
- Analyst: Includes everything a Member can do, plus full access to Optimize to build process dashboards and reports. Access to specific dashboards and reports within Optimize is governed separately by Optimize collection roles.
- Member: Full access to create and collaborate on workspaces and projects, plus read-only visibility into the organization.
- DevOps: A specialized role for infrastructure management, not people management. Grants cluster create and update, cluster clients, connector secrets, IP allowlisting, secure connectivity, encryption, and the connector-management view, plus Member-level modeling. Cannot manage or view organization members, billing, or organization settings.
Catalog access has two levels: Read-only (browse and use catalog items) for Member and DevOps, and Manage (also see usage statistics and adoption data) for Analyst, Organization Admin, and Organization Owner.
Environment access has two levels: Manage (view all environments and resume paused ones) for Organization Owner, Organization Admin, and DevOps, and Assigned only for Analyst and Member. Only Organization Owner and Organization Admin can assign environments to workspaces. Users with the Assigned only level see the environments assigned to the workspaces where they are an editor or a workspace admin.
Business value access includes viewing the business value dashboard and setting targets. The same roles that grant access to Optimize also grant access to business value.
Starting with version 8.8, user access to clusters' Operate, Tasklist, and Zeebe applications is managed independently of the organization role. To control what a user can access there, define their authorizations in the cluster's Admin.
If cluster authorizations are disabled, the user will have full access to the cluster and its components.
Elevated workspace access
Organization admins and owners always have Workspace Admin access to every workspace in the organization, including workspaces they aren't explicitly a member of. This access is on by default and can't be changed.
The main purpose of this access is to assign members to workspaces that have no members. Ordinarily, these workspaces would not be accessible or visible to any other users.
- SaaS
- Self-Managed
The user must be assigned the organization Organization Owner or Organization Admin role.
The user must be assigned the Hub Admin role.
If the role is not pre-existing, it can be created with the following permissions:
- Hub Internal API -
write:* - Hub Internal API -
admin:* - Camunda Identity Resource Server -
read:users
Refer to the documentation pages about assigning roles and adding permissions for detailed instructions.
Other roles
Beyond the roles above, an organization may show a few additional roles depending on its history:
- Developer (deprecated): No longer offered for new assignment. Existing holders keep their current permissions unchanged; they are not automatically moved to another role.
- Task user and Visitor (legacy): Available only for organizations with at least one cluster on version 8.7 or older, alongside a user's organization-level role. They govern access to the older cluster apps and disappear once no such clusters remain.
- Support agent (internal): Used only by the Camunda support team. Not assignable by customers.
Users are invited to a Camunda 8 organization via their email address, which must be accepted by the user. The user remains in the Pending state until the invitation is accepted.
People who do not yet have a Camunda 8 account can also be invited to an organization. To access the organization, the invited individual must first create a Camunda 8 account by following the instructions in the invitation email.
User task access restrictions
User task access restrictions were removed in Camunda 8.10 together with Tasklist V1.
Use authorization-based access control and user task authorization to control user access to tasks in the current version.