Feature · Operate & collaborate
Team access control with roles and audit logs.
Role-based access control (RBAC) gives each teammate only the permissions their job needs. On Runex, you invite teammates to a project, assign each a role, and every change they make is recorded in an audit log.
- Per-project roles
- Audit log of every change
- One-click offboarding
- priya
- admin
- jordan
- developer
- casey
- viewer
- last change
- env var updated · jordan
- audit log
- recording
Definition
What is role-based access control?
Role-based access control manages permissions by assigning people to roles, where each role has a defined set of allowed actions.
Instead of granting permissions person by person, you decide once what each role can do, then add people to roles.
On Runex, roles control who can deploy, change environment variables, manage domains, and invite others. A viewer can see deployments and logs; only admins can change settings or delete an app.
Every action (a deploy, a rollback, an env var change, a new member) is written to the project's audit log with who did it and when.
How it works
How does team access work on Runex?
Invite, assign a role, review the log.
-
You
Invite teammates
Add them to a project by email.
-
You
Assign roles
Admin, developer, or viewer.
-
Runex
Enforce permissions
Every action is checked against the role.
-
Runex
Record everything
The audit log keeps who did what, and when.
Benefits
Why use role-based access control?
Everyone can help; not everyone can break production.
Least privilege
People get only the access they need.
Safer secrets
Limit who can read or change env vars.
Clear accountability
Every change has a name and a time.
Easy offboarding
Remove a member and their access ends.
Compare
RBAC vs a shared account: what's the difference?
RBAC gives each person their own access; a shared login gives everyone the same keys.
| RBAC on Runex | Shared account | |
|---|---|---|
| Access | Per person, per role | Everyone has full access |
| Audit trail | Every action tied to a person | No way to tell who did what |
| Offboarding | Remove one member | Change the password for everyone |
| Risk | Mistakes are contained | Anyone can delete production |
Example
Example: a four-person product team
A small team shares one project safely: two people can deploy, one can only watch.
- The owner creates the acme/storefront project
- They invite a developer and an admin
- A contractor joins as a viewer
- The viewer checks logs but can't deploy
- The developer ships; the deploy is logged
- The contractor leaves; one click removes access
- deploy #88
- jordan · developer
- env change
- priya · admin
- deploy attempt
- casey · denied
- member removed
- casey
- audit log
- complete
What is an audit log?
A chronological record of actions in a system: who did what, and when. Teams use it for debugging, security reviews, and compliance.
What is the principle of least privilege?
Give each person and service only the access they need to do their job. It limits the damage a mistake or a stolen account can do.
Does Runex support single sign-on (SSO)?
No. Runex doesn't offer SAML or SSO today; each teammate signs in with their own Runex account.
Which Runex plan includes team access?
Team features are part of the Teams plan, which is in early access. See the pricing page for current availability.
Next step
Ship with team access control today.
Sign up, install the GitHub App, and deploy your first app. It's free to start.
