Click a user row to manage product permissions, account status, and notes. Unassigned lists people who have signed in but hold no product access yet (assign roles here).
Unassigned 0
| Name | Last Access | Logins | Updated By | |
|---|---|---|---|---|
| No unassigned users. | ||||
Portal Admins β
| Name | Last Access | Logins | Updated By | |
|---|---|---|---|---|
| Loading users⦠| ||||
Users β
| Name | Last Access | Logins | Updated By | |
|---|---|---|---|---|
| Loading users⦠| ||||
A role's policy is what it may do, written as product.component.action.function.
Tick a cell to hand the role everything a component allows at that action β
horizon.rds.read.* β or open a cell to pick individual permissions. A ticked
cell keeps covering controls shipped later; boxes ticked one by one do not, so
14 of 14 and all are the same access today and different
policies tomorrow. The pencil on a product page does the same job one control at a time;
start here and go there for exceptions. Super User holds
product.* by definition, including permissions that do not exist yet, so it
has no policy to edit.
Loading role policiesβ¦
Name people who may vouch others into the roles they hold themselves. On /grants/, a grantor can hand out any or all of their own roles, for the products listed here, and can revoke any grant they could have made themselves. Read Only comes with every role. Super User is never vouchable, and a grantor can neither change their own access nor appoint other grantors.
What this page sets is which products someone grants on. Pick a person below and their current products tick themselves β adjust and save to add or remove in one go. Remove in the table drops that one product only. Vouches as is not a setting: it follows the roles they hold themselves, so to widen what somebody may vouch, give them the role on the Users tab and it appears here.
| Name | Vouches as | Updated by | Remove | |
|---|---|---|---|---|
| Loading grantors⦠| ||||
Click a log row to view target resource, error details, and request metadata.
| Timestamp | Actor | Product | Action Type | Status |
|---|---|---|---|---|
| Loading⦠| ||||
Audit logs are stored in a separate D1 database (helix_audit_db).
Use this tool to remove old records and keep the database size manageable.
Loading usage dataβ¦
