> ## Documentation Index
> Fetch the complete documentation index at: https://docs.basaltic.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Assign account role

> Assign an account role to a user or group in the organization. The assignment grants permission to request role assumption, not direct resource access. The role trust policy must independently authorize the user. Changing a group assignment affects its human members.

<Info>
  Requires the IAM action **`workspace:AssignAccountRole`**. See [WORKSPACE permissions](/workspace/permissions) for the full list, what each one covers, and an example policy.
</Info>


## OpenAPI

````yaml /api-reference/specs/workspace.yaml post /v1/accounts/{account_id}/role-assignments
openapi: 3.0.3
info:
  title: Basaltic Workspace API
  version: 1.0.0
  description: >
    Organization management: organizations, accounts, human users, users-only
    groups, and organization policies. Account IAM identities may receive
    explicitly delegated organization policies through this API. Personal
    authentication remains at the IAM endpoint.


    Organization resources are global and are resolved in the authenticated
    organization. Canonical CRNs are
    crn:workspace:::organization/<organization-uuid>/<type>/<name-or-uuid>.
    Organization policies are separate from account policies; shared system
    policies use crn:workspace:::policy/<name>.
  contact:
    name: Basaltic Support
    email: ping@basaltic.sh
  license:
    name: Proprietary
    url: https://basaltic.sh/terms
servers:
  - url: https://workspace.basaltic.sh
    description: Global API endpoint
security:
  - BearerAuth: []
paths:
  /v1/accounts/{account_id}/role-assignments:
    parameters:
      - name: account_id
        in: path
        required: true
        schema:
          type: string
          format: uuid
    post:
      tags:
        - Workspace
      summary: Assign account role
      description: >-
        Assign an account role to a user or group in the organization. The
        assignment grants permission to request role assumption, not direct
        resource access. The role trust policy must independently authorize the
        user. Changing a group assignment affects its human members.
      operationId: assignAccountRole
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AccountRoleAssignmentCreateRequest'
      responses:
        '201':
          description: Account role assigned
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountRoleAssignmentResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
components:
  schemas:
    AccountRoleAssignmentCreateRequest:
      type: object
      additionalProperties: false
      required:
        - principal_type
        - principal_id
        - role_id
      properties:
        principal_type:
          type: string
          enum:
            - user
            - group
        principal_id:
          type: string
          format: uuid
          description: Immutable UUID of a user or users-only group in this organization.
        role_id:
          type: string
          format: uuid
          description: Immutable UUID of a role owned by the target account.
    AccountRoleAssignmentResponse:
      type: object
      properties:
        role_assignment:
          $ref: '#/components/schemas/AccountRoleAssignment'
    AccountRoleAssignment:
      type: object
      properties:
        crn:
          type: string
          description: >-
            Organization-qualified identity of this assignment in its target
            account.
          example: >-
            crn:workspace:::organization/550e8400-e29b-41d4-a716-446655440000/account/660e8400-e29b-41d4-a716-446655440000/role-assignment/770e8400-e29b-41d4-a716-446655440000
        id:
          type: string
          format: uuid
        account_id:
          type: string
          format: uuid
        role_id:
          type: string
          format: uuid
        role_name:
          type: string
        principal_type:
          type: string
          enum:
            - user
            - group
        principal_id:
          type: string
          format: uuid
        created_at:
          type: string
          format: date-time
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - request_id
          properties:
            code:
              type: string
              description: Error code identifying the type of error
              example: INVALID_INPUT
            message:
              type: string
              description: Human-readable error message
              example: Invalid request parameters
            request_id:
              type: string
              format: uuid
              description: Request ID for debugging
              example: 550e8400-e29b-41d4-a716-446655440000
  responses:
    BadRequest:
      description: Invalid request parameters
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INVALID_INPUT
              message: Invalid request parameters
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Unauthorized:
      description: Authentication required or token invalid
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: UNAUTHORIZED
              message: Authentication required
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Forbidden:
      description: Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: ACCESS_DENIED
              message: You don't have permission to perform this action
              request_id: 550e8400-e29b-41d4-a716-446655440000
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: NOT_FOUND
              message: Resource not found
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Conflict:
      description: Resource conflict (e.g., already exists, invalid state)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: CONFLICT
              message: Resource with this name already exists
              request_id: 550e8400-e29b-41d4-a716-446655440000
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: |
        An OAuth 2.0 bearer token, sent as `Authorization: Bearer <token>`.
        This is the recommended way to authenticate.

        Get one by exchanging a service account's access key pair at
        `POST /v1/oauth/token` with `grant_type=client_credentials`. It is the
        standard client-credentials grant, so any OAuth-aware library will
        obtain and refresh it for you.

        ```
        curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
          https://iam.basaltic.sh/v1/oauth/token
        ```

        Tokens last an hour by default. The same access key pair is separately
        your AWS SigV4 credential for the S3-compatible object endpoint, which
        speaks nothing else.

````