DevelopersDevelopers

Studio Roles

Gataca uses a scope-based strategy to manage roles and permissions. This means access to features in Studio is determined by the scopes assigned to a role, rather than the features being tied to specific roles.

By using scopes, you can precisely manage access and permissions, ensuring that each role has the appropriate level of access to Studio's features based on organizational needs.

Default Roles:

  • The scopes assigned to default roles are aligned with their descriptions, ensuring consistency and clarity in what each role can access.

Custom Roles:

  • When creating custom roles, you have the flexibility to tailor the roles to match your organization’s hierarchy and specific responsibilities.

Keep in mind that custom roles may not automatically align with predefined scopes, so you should carefully configure scopes to match the role’s intended access and functionality.

Roles

RoleDescriptionScopes
Provider Admin

This role manages a provider organization.

This kind of organization can manage its own platform, handling its clients and the organization stored there.

This role is accessible just to providers.

DeleteProviders, UpdateProviders, ReadProviders, CreateTenants, DeleteTenants, UpdateTenants, ReadTenants, CreateRoles, DeleteRoles, UpdateRoles, ReadRoles, CreateUsers, DeleteUsers, UpdateUsers, ReadUsers, CreateDids, DeleteDids, UpdateDids, RequestCatalogModifications, ReadDids, CreateSSIConfigs, DeleteSSIConfigs, UpdateSSIConfigs, ReadSSIConfigs, CreateApiKeys, DeleteApiKeys, UpdateApiKeys, ReadApiKeys
Organization Owner

This role manages a specific organization.

It has all the permissions needed to manage all the features attached to an organization, plus access to the billing and subscription section.

DeleteTenants, UpdateTenants, ReadTenants, CreateRoles, DeleteRoles, UpdateRoles, ReadRoles, CreateUsers, DeleteUsers, UpdateUsers, ReadUsers, CreateDids, DeleteDids, UpdateDids, RequestCatalogModifications, ReadDids, CreateSSIConfigs, DeleteSSIConfigs, UpdateSSIConfigs, ReadSSIConfigs, CreateApiKeys, DeleteApiKeys, UpdateApiKeys, ReadApiKeys, readSessions, validateSessions, issuanceProcesses, deleteSessions, readDataAgreements, updateDataAgreements, revokeDataAgreements, manageCredentials, manageSubscriptions
Tenant Admin

This role manages all the technical features in an organization.

This role has been created for the person in charge of the organization's technical area.

UpdateTenants, ReadTenants, CreateRoles, DeleteRoles, UpdateRoles, ReadRoles, CreateUsers, DeleteUsers, UpdateUsers, ReadUsers, CreateDids, DeleteDids, UpdateDids, RequestCatalogModifications, ReadDids, CreateSSIConfigs, DeleteSSIConfigs, UpdateSSIConfigs, ReadSSIConfigs, CreateApiKeys, DeleteApiKeys, UpdateApiKeys, ReadApiKeys
DID OwnerThis role manages a specific DID in the organization. Depending on the organization's hierarchy, it could be used to split responsibilities between departments, companies, etc.DeleteDids, UpdateDids, RequestCatalogModifications, ReadDids, CreateSSIConfigs, DeleteSSIConfigs, UpdateSSIConfigs, ReadSSIConfigs, CreateApiKeys, DeleteApiKeys, UpdateApiKeys, ReadApiKeys
SSI Config ManagerThis role can manage SSI Configs attached to a particular logical area (Tenants, DIDs, SSI Configs..). Depending on the organization's hierarchy, it could be used to split responsibilities between departments, companies, etc.CreateSSIConfigs, ReadSSIConfigs, UpdateSSIConfigs, DeleteSSIConfigs
API Key ManagerThis role can manage API Keys attached to a concrete logical area (Tenants, DIDs, SSI Configs, API Keys..). Depending on the organization's hierarchy, it could split responsibilities between departments, companies, etcCreateApiKeys, ReadApiKeys, UpdateApiKeys, DeleteApiKeys
OperatorThis role can manage sessions attached to a concrete logical area (Tenants, DIDs, SSI Configs..). Depending on the organization's hierarchy, it could be used to split responsibilities between departments, companies, etc.readSessions, validateSessions, issuanceProcesses, deleteSessions, readDataAgreements, updateDataAgreements, revokeDataAgreements, manageCredentials

Scopes

ScopeDescription
readProvidersIt allows the user to read all the providers on the platform.
updateProvidersIt allows the user to update the providers to it has permission.
deleteProvidersIt allows the user to delete the providers to it has permission.
createTenantsIt allows the user to create a new organization in the platform.
readTenantsIt allows the user to read all organizations to it has permission.
updateTenantsIt allows the user to update all organizations to it has permission.
deleteTenantsIt allows the user to delete all organizations to which it has permission.
createRolesIt allows the user to create new custom roles. The new role created will be accessible in the tenant associated.
readRolesIt allows the user to read all the roles in the tenant to which it has permission.
updateRolesIt allows the user to update all the roles in the tenant to which it has permission.
deleteRolesIt allows the user to delete all the roles in the tenant to which it has permission.
createUsersIt allows the user to invite new users to a specific organization.
readUsersIt allows the user to read all users of an organization.
updateUsersIt allows the user to update all users of a specific organization.
deleteUsersIt allows the user to delete all users of a specific organization.
createDidsIt allows the user to create new DIDs for a specific organization.
readDidsIt allows the user to read the DIDs of a specific organization.
updateDidsIt allows the user to update the DIDs of a specific organization.
deleteDidsIt allows the user to delete the DIDs of a specific organization.
requestCatalogModificationsCOMING SOON: It has already been developed in the backend but is not visible in the front (This scope is required to create “requests” to Gataca Admins).
createSSIConfigsIt allows the user to create issuance and verification templates for a specific organization.
readSSIConfigsIt allows the user to read issuance and verification templates of a specific organization.
updateSSIConfigsIt allows the user to update issuance and verification templates of a specific organization.
deleteSSIConfigsIt allows the user to delete issuance and verification templates of a specific organization.
createApiKeysIt allows the user to create API Keys for a specific organization.
readApiKeysIt allows the user to read the API Keys of a specific organization.
updateApiKeysIt allows the user to update the API Keys of a specific organization.
deleteApiKeysIt allows the user to delete API Keys of a specific organization.
readSessionsIt allows the user to read sessions from issuance or verification requests of a specific organization. Reading all the instances of issuance and verification templates for an organization is possible.
validateSessionsIt allows the user to validate issuance requests of an organization and fill the information related to that issuance process.
deleteSessionsIt allows the user to delete sessions from issuance or verification requests of an organization.
readDataAgreementsIt allows the user to read an organization's data agreements (consents).
updateDataAgreementsIt allows the user to update a specific organization's data agreements (consents).
revokeDataAgreementsIt allows the user to revoke a specific organization's data agreements (consents).
manageCredentialsIt allows the user to change the status of a credential (issued, revoked, suspended).
manageSubscriptionIt allows the user to update the subscription and billing attached to the organization.