Skip to content
EN

Roles and Permissions

Last updated

Inviting members, assigning roles (permissions), and managing a workspace are configured in Re:Earth Dashboard, which is shared across all products. For details, see the Dashboard documentation (in preparation).

The role assigned in Dashboard determines what that member can do in Re:Earth CMS. There are four roles.

RoleWhat the role can do in the CMS
OwnerCan perform every operation in the CMS. Only Owner can create and delete a project and regenerate an API key
MaintainerCan change project settings and operate models, schemas, items, assets, and requests
WriterCan create, edit, and delete models, schemas, and views. Can create items, assets, requests, and comments, and can edit and delete the ones they created themselves
ReaderCan only view

The operations each role can perform in the CMS are as follows. ✓ means it can be done and ✕ means it cannot.

ResourceOperationOwner / MaintainerWriterReader
ModelView
ModelCreate, edit, delete
SchemaView
SchemaCreate, edit, delete
ItemView
ItemCreate
ItemEdit, deleteOnly items they created
ItemPublish
AssetView
AssetCreate
AssetEdit, deleteOnly assets they created
ViewView
ViewCreate, edit, delete
RequestView
RequestCreate
RequestEdit, closeOnly requests they created
RequestApprove
CommentView
CommentCreate
CommentEdit, deleteOnly comments they created

“Publish” in the table is a base permission. Whether an item can actually be published directly depends on the project’s request requirement. For a role where a request is required, publishing becomes creating a request instead. For details, see Request.

“Approve” in the table is also a base permission. A request can actually be approved by the person who is assigned as a reviewer for that request.

Only Owner and Maintainer can change project settings such as the name and the alias. Switching the visibility and changing the posting settings in Public API settings are also limited to Owner and Maintainer. Only Owner can create and delete a project and regenerate an API key.