Permissions and API Keys
DBOS Conductor controls access to your organization's applications, workflows, and settings using role-based access control (RBAC) for users and scoped API keys for applications and automation. This page describes the permission model, the built-in and custom roles, and how to create and manage API keys.
You manage permissions and API keys from the DBOS Console.
Permissions
Every action in Conductor, like viewing a workflow, registering an application, or creating an API key, requires a specific permission.
| Permission | Grants the ability to |
|---|---|
organization.read | View organization details, members, and roles. |
organization.write | Manage the organization: rename it, add and remove members, create and assign roles, manage billing. |
application.read | View applications and their workflows, queues, schedules, executors, and alerting rules. |
application.write | Register, update, and delete applications; manage workflows (cancel, resume, fork, delete, import); and manage schedules and alerting rules. |
metric.read | Read application metrics, including the Prometheus-compatible metrics endpoint. |
token.read | List API keys. |
token.write | Create and revoke API keys. |
websocket.connect | For an API key, connect a running application executor to Conductor over its websocket. |
Roles
A role is a named set of permissions. Each member of an organization is assigned exactly one role, which determines everything they can do in that organization.
Built-in roles
Every organization has two built-in roles:
| Permission | Organization Member | Organization Admin |
|---|---|---|
organization.read | ✅ | ✅ |
organization.write | ✅ | |
application.read | ✅ |