Roles and groups
Roles answer “what can this person do?”. Built-in roles control the TrustPort dashboard; custom roles travel in each user’s token so your own product can decide.
Built-in roles
| Role | In the TrustPort dashboard and API |
|---|---|
| owner | Full control, including making other people owners |
| admin | Can change everything except granting or removing the owner role |
| viewer | Can see everything, change nothing, and can’t reveal stored secrets |
| member | Signs in, but has no dashboard access |
| No role | Signs in to your app, but has no dashboard access |
Everyone can manage their own account, password, two-factor devices and sessions, whatever their role.
Custom roles for your product
- Name the role
Use a short, stable name your code will check, like
billing_manager. - List what it allows
One permission per line, written as
resource:action:scope, for exampleinvoices:read:tenant. These describe the role for your team; your app decides what to enforce.
Then check the role in your app using the roles claim in the user's access token:
// After verifying the access token
if (!claims.roles.includes('billing_manager')) {
return res.status(403).json({ error: 'Billing access required' })
}Give someone a role
- Find the user
Search by email or username.
- Pick a role and, optionally, an end date
Set an expiry for temporary access, like a contractor's project or an on-call week. The role stops applying on its own when the date passes.
The change applies the next time their token is refreshed, within 15 minutes. To apply it straight away, ask them to sign out and back in.
curl -X POST https://id.trustportidentity.com/api/v1/roles/assign \
-H "Authorization: Bearer $TRUSTPORT_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "user_id": "<user-id>", "role_name": "billing_manager", "expires_at": "2026-12-31T23:59:59Z" }'Groups
Groups collect people you manage together, such as finance-team. Create a group, then add or remove members from it. Groups are also where people from a customer's directory will land once Directory Sync arrives.
Ask for access instead of granting it
For sensitive roles, let people request access and have someone else approve it. See Access requests and reviews.