π€ Users & Teams
Skylogs uses a simple, role-based system to manage user permissions and access to alert rules, endpoints, and teams.
This document explains how users are created, how roles work, and how teams are managed.
π₯ User Roles
Skylogs includes three user roles:
- Owner
- Manager
- Member
Role permissions determine what each user can see, create, and modify.
π‘ Role Permissions Overviewβ
| Action | Owner | Manager | Member |
|---|---|---|---|
| Create users | βοΈ (Manager or Member) | βοΈ (Member only) | β |
| View Users page | βοΈ | βοΈ | β |
| Create teams | βοΈ | βοΈ | β |
| Edit/Delete teams | βοΈ | βοΈ | β |
| View teams | βοΈ | βοΈ | βοΈ |
| Create endpoints | βοΈ | βοΈ | βοΈ |
| Edit/Delete all endpoints | βοΈ | βοΈ | β |
| Edit/Delete own endpoints | βοΈ | βοΈ | βοΈ |
| Set access to endpoints & alert rules | βοΈ | βοΈ | βοΈ |
| Create alert rules | βοΈ | βοΈ | βοΈ |
π€ Users
System Owner (Admin)β
- The system automatically creates a single admin user with the Owner role.
- This user is the only one who starts with Owner permissions.
Creating Usersβ
-
Owner can create new users with either:
- Manager
- Member
-
Manager can create only Member users.
-
Member users cannot create users and cannot see the Users section.
User Visibilityβ
- Owners and managers have access to the Users menu.
- Members do not have access to this section.
π¨βπ©βπ§ Teams
Teams allow grouping multiple users to simplify access control for alert rules and endpoints.
Users with access to a team automatically gain access to resources shared with that team.
Team Structureβ
Each team has:
- Team Owner (a user with Owner or Manager permissions)
- Team Members (users of any role)
Team Permissionsβ
| Action | Owner | Manager | Member |
|---|---|---|---|
| Create team | βοΈ | βοΈ | β |
| Edit team | βοΈ | βοΈ | β |
| Delete team | βοΈ | βοΈ | β |
| View team details | βοΈ | βοΈ | βοΈ |
| Add/remove team members | βοΈ | βοΈ | β |
Members can see team owners and members but cannot modify teams.
π Access Control (Users & Teams)
Skylogs provides a flexible sharing model for both:
- Alert Rules
- Endpoints
Users can grant access to either:
- Specific users
- Entire teams
Sharing Behaviorβ
- Shared users and teams receive read-only access.
- Only users with appropriate roles (Owner/Manager/Owner-of-resource) can edit or delete.
- Access can be shared with multiple users or teams at once.
Examplesβ
- Share an alert rule with the βOps Teamβ to notify everyone in operations.
- Share a critical SMS endpoint with a specific user so the user can set the endpoint to his/her alert rules that has access.
π Navigation in the UI
If you are an Owner or Managerβ
You can see Users and Teams menu items
If you are a Memberβ
You see only Teams
Members do not see the Users section and cannot create/edit/delete teams.
β¨ Summary
Skylogs uses a simple and powerful structure:
Usersβ
- Owner β full control
- Manager β manages members and teams
- Member β limited user without administrative permissions
Teamsβ
- Created by owners/managers
- Each team has an owner and members
- Members can only view team info
Access Controlβ
- Endpoints and alert rules can be shared with users or teams
- Shared access is always read-only
- Ownership determines who can edit/delete