Product guide

Ownership, access, and operations control

Organization/project ownership, tasks, roles, storage, identity, and audit scope for multi-team use.

Content statusVerified in sourceDocumentation versionLatest

Control plane

  • Organization, project, and repository ownership
  • Durable task state, progress, retries, and failure records
  • Six fixed roles and resource-scoped access policy
  • Audit, package-usage, operation, and outbound logs
  • LDAP, Google, generic OIDC, and API tokens

Ownership and authorization model

Organization provides the top ownership scope, project provides working context, and repository provides the package-access boundary. Fixed roles govern platform functions, while access policies bound to user, group, or anonymous subjects restrict actions on resources.

Task and record surfaces

Long-running work produces durable task state, progress, retry, and failure summaries. Audit records administrative changes, Package Usage records package requests, Operation records background work, and Outbound records external-system access for distinct purposes.

  • Owner, start and finish time, status, counters, and error summary for each critical task
  • Actor and resource scope on the audit record for each administrative change
  • Reconciliation of package access with Package Usage and, where applicable, the firewall decision
  • Outbound or Operation evidence that separates external-connection failure from user error

Enterprise responsibility boundary

The platform provides role and record mechanisms, but identity-provider lifecycle, group ownership, log retention, task intervention, and secret rotation must be defined by the adopting organization. Published scope does not claim certification or automatic compliance with a specific regulation.