Skip to main content

Permissions Matrix

This page is the centralized permission reference for CAIP Web Portal features.

Quick links: New User Flow | Pre-Space Actions | Feature-Level Matrix

How to read this table
  • Y = action is available in the portal context
  • N = action is not available in the portal context
  • In the feature table, permissions are shown as C/R/U/D inside each role column.
  • The feature matrix below applies after a user is inside a Space context.
  • Effective access can vary by assigned scopes and environment configuration.
  • Scope options are exposed by GET /v1/scopes/catalog.

Pre-Space Actions (Service Request)

Space creation is a pre-space lifecycle action, so Owner/Member roles do not apply yet.

ActionWho Can Do ItOutcome
Raise Space Creation RequestAny portal userA new Space is provisioned via Service Request, and the requester becomes the Space Owner.

Currently, space creation is allowed only via Service Request. Soon, users will be able to raise a new space request directly from the portal.


Feature-Level Matrix

FeatureOwner (C/R/U/D)Member (C/R/U/D)Notes
SpacesN/Y/Y/NN/Y/N/NSpace creation is handled via Service Request before Space context. In-space actions cover view/update only.
MembersY/Y/Y/YN/Y/N/NMember management is owner-only in Identity & Access.
M2M ClientsY/Y/Y/YY/Y/Y/YMember operations depend on assigned scopes.
API KeysY/Y/Y/YY/Y/Y/YMember operations depend on assigned scopes.
Agent ManagementY/Y/Y/YY/Y/Y/YAgent metadata CRUD in portal.
CDH LinksY/Y/Y/YY/Y/Y/YLink management is available to owner/member roles.
CostN/Y/N/NN/Y/N/NVisibility and analytics only.
Model CatalogN/Y/N/NN/Y/N/NBrowse and compare models only.

Validation Sources

  • Scope catalog endpoint: GET /v1/scopes/catalog
  • Portal behavior should follow assigned scopes and role mappings deployed in the active environment.
  • Permissions can vary by environment rollout and policy configuration.