Roles
Permission sets, who holds them, and every change made to one.
List roles
Returns the workspace's roles with the permissions each grants, plus role_users_count — how many active members currently hold it.
query Parameters
cursor^[A-Za-z0-9_-]+$limitoffsetrole_activerole_idrole_managed_byrole_namerole_permissionssort^-?[a-z0-9_]+$Headers
X-Tenant-IdThe workspace this request acts in. Every row the API returns is isolated to it at the database layer by row-level security.
List roles › Responses
Success
has_moreWhether more rows exist past this page.
next_cursorPass back as cursor for the next page. Null on the last page.
Create a role
A role is a set of permissions. What its holders can actually do is that set narrowed by the plan — granting a permission the plan does not include has no effect until the plan does.
Headers
X-Tenant-IdThe workspace this request acts in. Every row the API returns is isolated to it at the database layer by row-level security.
Create a role › Request Body
role_namerole_activeCreate a role › Responses
Created
role_idrole_namerole_descriptionrole_iconrole_permissionsrole_managed_byrole_activerole_createdrole_users_countGet a role
Returns the role with the permissions it grants. What a member of it may actually do is that set narrowed by the workspace's plan.
path Parameters
idHeaders
X-Tenant-IdThe workspace this request acts in. Every row the API returns is isolated to it at the database layer by row-level security.
Get a role › Responses
Success
role_idrole_namerole_descriptionrole_iconrole_permissionsrole_managed_byrole_activerole_createdrole_users_countUpdate a role
Takes effect for everyone holding the role, on their next request.
path Parameters
idHeaders
X-Tenant-IdThe workspace this request acts in. Every row the API returns is isolated to it at the database layer by row-level security.
Update a role › Responses
Success
role_idrole_namerole_descriptionrole_iconrole_permissionsrole_managed_byrole_activerole_createdrole_users_countList role history
Every recorded change, newest first, each as a per-field {from, to} changeset.
path Parameters
idHeaders
X-Tenant-IdThe workspace this request acts in. Every row the API returns is isolated to it at the database layer by row-level security.
List role history › Responses
Success
history_idhistory_timestamphistory_userhistory_opThe kind of change — insert, update or delete.
One entry per field that changed, keyed by column name.
history_refWhat the writer noted about the change rather than the columns: the action that made it, or the reason it was made.
