IDENTITY
Roles & Permissions
Decide who can do what in your application — with roles, permissions and policies for users, projects, resources and service accounts.
Roles
acme / my-app / productionROLEASSIGNED TOPERMISSIONS
admin Users*
editor Usersposts:read, posts:write
ci-deployer Service accountdeploy:run
Permission check can(user, 'posts:write', project:acme-blog) → allow
WHAT IT DOES
Access control your app can rely on.
Define roles and permissions for your application, write policies for sensitive actions, and grant access at the project or resource level. Give service accounts scoped access for machine-to-machine calls.
Controls access for your application's users — separate from Stack53 workspace member roles.Roles and policies are defined per environment.One permission check for users and service accounts.Works with Authentication, Users and OAuth.
KEY CAPABILITIES
Model the access rules you need.
Roles Group permissions into roles like admin, editor or viewer.
Permissions Name the actions in your app, such as posts:write.
Policies Add conditions to rules, such as ownership or account status.
Project access Grant users access to projects and teams in your app.
Resource permissions Scope permissions to individual records and resources.
Service accounts Non-human identities for backend jobs and integrations.
Machine access Scoped credentials for machine-to-machine calls.
Permission checks Ask one question: can this identity do this, here?
Authorization API Manage roles and check access from the API and SDKs.
HOW IT WORKS
Set up access control in four steps.
- 01 Define permissions Name the actions your app supports.
- 02 Group them into roles Admin, editor, viewer — or your own.
- 03 Assign roles To users and service accounts, per project or resource.
- 04 Check access Call one check before every sensitive action.
COMMON USE CASES
Where teams add access control.
Multi-tenant SaaS Separate admins, members and viewers inside each customer's projects.
Content and workflows Let editors publish and reviewers approve, with rules per resource.
Backend automation Give jobs and integrations service accounts instead of user credentials.
DEVELOPER INTEGRATION
Built for code.
Create roles, assign them to users and service accounts, and check permissions from the REST API or the SDKs.
await stack53.authz.roles.create({
name: 'editor',
permissions: ['posts:read', 'posts:write'],
})
await stack53.authz.assign(user.id, 'editor', { project })
// Check before every write
const ok = await stack53.authz.can(user.id, 'posts:write')
SECURITY Least privilege, built in. Grant only the permissions each role needs.Service account credentials can be rotated or revoked.Role and policy changes recorded in audit logs.Encrypted connections for every API call. Security at Stack53 →
AVAILABILITY Where it runs.
REGIONOPERATED BYSTATUS
Canada Central[Partner / Stack53][Status]
Canada East[Partner / Stack53][Status]
Put the right access in place.
Start building on Stack53, or talk to us about identity requirements and data residency.