> ## Documentation Index
> Fetch the complete documentation index at: https://docs.basaltic.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Workspace permissions

> Organization actions, account role assignments, and delegation to account identities.

Workspace serves organization resources at `workspace.basaltic.sh`. Grant
`workspace:*` actions in organization policies. Billing, quota, and audit
actions are also evaluated in the organization policy domain.
Account IAM policies never grant these actions, even with an action wildcard.

Users inherit organization policies directly and through user groups. Roles
and service accounts receive only organization policies explicitly delegated
to them. A role session uses the role's grants, not those of its source.

## Resource names

```
crn:workspace:::organization/<organization-uuid>
crn:workspace:::organization/<organization-uuid>/account/<account-uuid>
crn:workspace:::organization/<organization-uuid>/user/<user-uuid>
crn:workspace:::organization/<organization-uuid>/group/platform-team
crn:workspace:::organization/<organization-uuid>/policy/billing-reader
crn:workspace:::policy/Administrator
```

Groups and custom policies use immutable names. Accounts, users, and invitations
use UUIDs. An account's display name is not its handle or its CRN identity.
Top-level lists authorize their collection, not each result; query filters do
not replace authorization.

User and group inline policies append `/inline-policy/<name>` to the principal
CRN. A user's permission boundary appends `/permission-boundary/default`.
Setting that boundary also requires `workspace:GetPolicy` on the chosen policy.

## The actions

The table includes primary actions. Additional target-account checks for
organization delegation and role assignment are described below.

| Call                                                                    | Action                                  |
| ----------------------------------------------------------------------- | --------------------------------------- |
| `GET /v1/organizations`                                                 | `none`                                  |
| `GET /v1/organizations/{organization_id}`                               | `workspace:GetOrganization`             |
| `PATCH /v1/organizations/{organization_id}`                             | `workspace:UpdateOrganization`          |
| `DELETE /v1/organizations/{organization_id}`                            | `workspace:DeleteOrganization`          |
| `GET /v1/accounts`                                                      | `workspace:ListAccounts`                |
| `POST /v1/accounts`                                                     | `workspace:CreateAccount`               |
| `GET /v1/accounts/{account_id}/resources`                               | `workspace:GetAccount`                  |
| `GET /v1/accounts/{account_id}`                                         | `workspace:GetAccount`                  |
| `PATCH /v1/accounts/{account_id}`                                       | `workspace:UpdateAccount`               |
| `DELETE /v1/accounts/{account_id}`                                      | `workspace:DeleteAccount`               |
| `GET /v1/invitations`                                                   | `workspace:ListInvitations`             |
| `GET /v1/invitations/{invitation_id}`                                   | `workspace:GetInvitation`               |
| `DELETE /v1/invitations/{invitation_id}`                                | `workspace:CancelInvitation`            |
| `GET /v1/users`                                                         | `workspace:ListUsers`                   |
| `POST /v1/users`                                                        | `workspace:AddUser`                     |
| `GET /v1/users/{user_id}`                                               | `workspace:GetUser`                     |
| `DELETE /v1/users/{user_id}`                                            | `workspace:RemoveUser`                  |
| `GET /v1/users/{user_id}/policies`                                      | `workspace:ListUserPolicies`            |
| `POST /v1/users/{user_id}/policies`                                     | `workspace:AttachPolicy`                |
| `DELETE /v1/users/{user_id}/policies/{policy_id}`                       | `workspace:DetachPolicy`                |
| `GET /v1/users/{user_id}/groups`                                        | `workspace:ListUserGroups`              |
| `POST /v1/users/{user_id}/groups`                                       | `workspace:ManageGroupMembership`       |
| `DELETE /v1/users/{user_id}/groups/{group_id}`                          | `workspace:ManageGroupMembership`       |
| `GET /v1/service-accounts/{service_account_id}/policies`                | `workspace:ListServiceAccountPolicies`  |
| `POST /v1/service-accounts/{service_account_id}/policies`               | `workspace:AttachServiceAccountPolicy`  |
| `DELETE /v1/service-accounts/{service_account_id}/policies/{policy_id}` | `workspace:DetachServiceAccountPolicy`  |
| `GET /v1/groups`                                                        | `workspace:ListGroups`                  |
| `POST /v1/groups`                                                       | `workspace:CreateGroup`                 |
| `GET /v1/groups/{group_id}`                                             | `workspace:GetGroup`                    |
| `PATCH /v1/groups/{group_id}`                                           | `workspace:UpdateGroup`                 |
| `DELETE /v1/groups/{group_id}`                                          | `workspace:DeleteGroup`                 |
| `GET /v1/groups/{group_id}/users`                                       | `workspace:ListGroupUsers`              |
| `GET /v1/groups/{group_id}/policies`                                    | `workspace:ListGroupPolicies`           |
| `POST /v1/groups/{group_id}/policies`                                   | `workspace:AttachPolicy`                |
| `DELETE /v1/groups/{group_id}/policies/{policy_id}`                     | `workspace:DetachPolicy`                |
| `GET /v1/roles/{role_id}/policies`                                      | `workspace:ListRolePolicies`            |
| `POST /v1/roles/{role_id}/policies`                                     | `workspace:AttachRolePolicy`            |
| `DELETE /v1/roles/{role_id}/policies/{policy_id}`                       | `workspace:DetachRolePolicy`            |
| `GET /v1/policies`                                                      | `workspace:ListPolicies`                |
| `POST /v1/policies`                                                     | `workspace:CreatePolicy`                |
| `GET /v1/policies/{policy_id}`                                          | `workspace:GetPolicy`                   |
| `PATCH /v1/policies/{policy_id}`                                        | `workspace:UpdatePolicy`                |
| `DELETE /v1/policies/{policy_id}`                                       | `workspace:DeletePolicy`                |
| `GET /v1/policies/{policy_id}/users`                                    | `workspace:GetPolicy`                   |
| `GET /v1/policies/{policy_id}/service-accounts`                         | `workspace:GetPolicy`                   |
| `GET /v1/policies/{policy_id}/groups`                                   | `workspace:GetPolicy`                   |
| `GET /v1/policies/{policy_id}/roles`                                    | `workspace:GetPolicy`                   |
| `PUT /v1/users/{user_id}/permission-boundary`                           | `workspace:SetPermissionBoundary`       |
| `GET /v1/users/{user_id}/permission-boundary`                           | `workspace:GetPermissionBoundary`       |
| `DELETE /v1/users/{user_id}/permission-boundary`                        | `workspace:RemovePermissionBoundary`    |
| `GET /v1/users/{user_id}/inline-policies`                               | `workspace:ListInlinePolicies`          |
| `PUT /v1/users/{user_id}/inline-policies/{policy_name}`                 | `workspace:PutInlinePolicy`             |
| `GET /v1/users/{user_id}/inline-policies/{policy_name}`                 | `workspace:GetInlinePolicy`             |
| `DELETE /v1/users/{user_id}/inline-policies/{policy_name}`              | `workspace:DeleteInlinePolicy`          |
| `GET /v1/groups/{group_id}/inline-policies`                             | `workspace:ListInlinePolicies`          |
| `PUT /v1/groups/{group_id}/inline-policies/{policy_name}`               | `workspace:PutInlinePolicy`             |
| `GET /v1/groups/{group_id}/inline-policies/{policy_name}`               | `workspace:GetInlinePolicy`             |
| `DELETE /v1/groups/{group_id}/inline-policies/{policy_name}`            | `workspace:DeleteInlinePolicy`          |
| `GET /v1/accounts/{account_id}/role-assignments`                        | `workspace:ListAccountRoleAssignments`  |
| `POST /v1/accounts/{account_id}/role-assignments`                       | `workspace:AssignAccountRole`           |
| `DELETE /v1/accounts/{account_id}/role-assignments/{assignment_id}`     | `workspace:RemoveAccountRoleAssignment` |
| `GET /v1/account-roles`                                                 | `none`                                  |

Human members can read their own organization through membership. Machine
identities need `workspace:GetOrganization`. Organization listing returns the
human's memberships. Personal sign-in, invitation acceptance, and switching the
active organization remain IAM authentication flows.

## Attaching organization policies to people

`workspace:AttachPolicy` and `workspace:DetachPolicy` require authorization on
both the organization policy and target user or group. Use the concrete CRNs
of both resources; system policies have their separate system CRN namespace.

## Delegating organization policies

A role or service account can carry organization permissions for billing
collectors, onboarding jobs, or other automation. Its console policy tab has
separate **Account policies** and **Organization policies** tables.

The organization attachment endpoints are on Workspace, not IAM:

| Target          | Workspace path                                       |
| --------------- | ---------------------------------------------------- |
| Role            | `/v1/roles/{role_id}/policies`                       |
| Service account | `/v1/service-accounts/{service_account_id}/policies` |

POST accepts `policy_id`, the organization's policy UUID. DELETE appends that
UUID to the path. GET lists the organization's policy attachments.
The target's UUID is resolved within the current organization and its owning
account; it does not move the caller's identity into that account.

The same caller must satisfy both checks:

| Operation                                | Organization permission                                                                            | Target-account permission                         |
| ---------------------------------------- | -------------------------------------------------------------------------------------------------- | ------------------------------------------------- |
| List a role's grants                     | `workspace:ListRolePolicies` on the role CRN                                                       | `iam:GetRole` on the role                         |
| Attach or detach a role grant            | `workspace:AttachRolePolicy` or `workspace:DetachRolePolicy` on the policy CRN                     | `iam:UpdateRole` on the role                      |
| List a service account's grants          | `workspace:ListServiceAccountPolicies` on its CRN                                                  | `iam:GetServiceAccount` on the service account    |
| Attach or detach a service account grant | `workspace:AttachServiceAccountPolicy` or `workspace:DetachServiceAccountPolicy` on the policy CRN | `iam:UpdateServiceAccount` on the service account |

Combining two credentials is not supported. Use an identity that holds the
required organization grant and target-account permission, or an organization
owner performing initial setup. An account role with no organization grants
cannot attach them to itself.

Sensitive changes that transfer an already delegated identity's authority also
require Workspace delegation permission. Account policy administration alone
cannot obtain organization access by passing a role or issuing a new credential.

## Account role assignments

Role assignments bind an organization user or group to a role in one account.
They supply the source permission for a human's AssumeRole exchange. Target
trust is still required, and assignment creation never changes trust.

Creating an assignment requires `workspace:AssignAccountRole` plus
`iam:GetRole` for the target role. Listing and removing assignments use
`workspace:ListAccountRoleAssignments` and
`workspace:RemoveAccountRoleAssignment`.

The current human can discover their effective assignments through
`GET /v1/account-roles`. This is distinct from the administrative account list;
a user need not receive `workspace:ListAccounts` simply to choose an assigned
role. See [account access](/workspace/accounts).
