Last reviewed Feb 16, 2026 (6 months ago). Reuse count: 15.
Role-based access control with the principle of least privilege. Standard roles include Viewer, Contributor, Approver, and Workspace Admin. Customers can also define custom roles via API. Permissions are evaluated at request time; every authorization decision is logged with the requesting principal, resource, and decision rationale.
Source: RBAC model