IAM & Access

Users, Groups, and Roles

Manage direct and inherited organisation access with members, groups, and roles.

Users are invited into organisations. IAM roles define what a user or service account can do, while groups make the same role access easy to apply to several identities.

For basic organisation administration, start with Members and Invitations and Member Roles.

Users

A user is a person who can sign in to Infuse and access one or more organisations.

Open Access > Members to manage active members. Invitations are in the Invitations view within Members.

Each member has exactly one baseline membership level: Owner, Admin, or Member. A member can also receive any number of additional compatible IAM roles directly or through groups. These sources are cumulative.

Select Manage access or View access beside a member to open their detail page. Its Access view shows:

  • the member's baseline membership level,
  • additional roles assigned directly,
  • direct permission grants,
  • roles inherited through groups,
  • current effective permissions and the source of each permission.

Owners and administrators can change eligible membership levels from this page. Only owners can assign or remove the Owner level.

The member's API keys view shows metadata for personal API keys. Members issue their own keys from Account > API keys; authorised administrators can inspect or revoke a key but cannot reveal or issue it for someone else.

Groups

Groups collect users and service accounts so access can be managed in one place.

Use groups when:

  • multiple people or workloads need the same access,
  • a team or set of integrations changes often,
  • you want to remove or add access without editing each identity,
  • you need a consistent access pattern across product workflows.

Create a Group

  1. Open Access > Groups.
  2. Select Create group.
  3. Enter a group name.
  4. Add an optional description.
  5. Select the users and service accounts that should belong to the group.
  6. Save the group.

The group belongs to the active organisation. If you switch organisations, the groups list changes to that organisation.

Manage Group Membership and Roles

Open Access > Groups, then select the group. The group page has separate Members and Assigned roles views.

From Members, update the name, description, or selected identities. Before saving, the Portal shows how many will be added or removed and warns when the change affects inherited access. An identity cannot be added if it is incompatible with a role already assigned to the group.

From Assigned roles, select Assign role, choose a compatible organisation role, and confirm the assignment. Every current member inherits the role immediately, and compatible members added later inherit it automatically. Save or discard pending membership changes before assigning another role.

To remove inherited access, revoke the role from the group. To retire the group, delete it from the groups list. The Portal warns when deleting a group will remove inherited role access from its members.

Roles

Roles describe what a user or service account can do. A role contains one or more permissions and declares which principal types can receive it. A role can also limit compatible permissions to particular resources and require time-based conditions.

Use Access > Roles to review roles available to the active organisation. The list identifies organisation-owned roles and Infuse-provided shared templates, along with permission counts and supported principal types.

Review a Role

Open a role to see:

  • an overview and supported principal types,
  • permissions and any resource limits,
  • direct identity and group assignments,
  • conditions that must match before the role grants access.

Use the assignment filters to separate directly assigned identities from groups. Group assignments display how many current members inherit the role.

Create or Clone a Role

Select Create role from Access > Roles to create a role owned by the active organisation. Enter a name and optional description, choose at least one supported principal type, select permissions, and add any required resource limits or conditions.

Infuse-provided shared templates are read-only. Open a template and select Clone to create an editable organisation-owned copy with the same permissions, resource limits, conditions, and principal types.

Edit or Delete an Organisation Role

Open an organisation-owned role and select Edit. You can change its name, description, principal types, permissions, resource limits, and conditions. The Portal warns when a change may remove or broaden existing access.

Deleting an organisation role stops its existing assignments from granting access. Shared templates cannot be edited or deleted.

Assign and Revoke Roles

To assign a role from the role page:

  1. Open Access > Roles.
  2. Open the role.
  3. Select Assign role.
  4. Choose compatible users, service accounts, or groups.
  5. Select Assign.

You can also assign an additional role from a member's Access view, a service account's Access tab, or a group's Assigned roles view.

Revoke a direct assignment from the same identity page or from the role's Assignments view. Revoking a group assignment removes that inherited role from every current group member; it does not remove those identities from the group.

Check Effective Access

Open a member or service account and select its Access view. Effective permissions is the current access result. Source sections explain direct roles, group-inherited roles, and direct grants.

An assignment can appear in a source list without producing a current effective permission, for example when it has not started, has expired, has an unmet condition, or is limited to another resource.