TrustPortDocs

Built-in roles

RoleIn the TrustPort dashboard and API
ownerFull control, including making other people owners
adminCan change everything except granting or removing the owner role
viewerCan see everything, change nothing, and can’t reveal stored secrets
memberSigns in, but has no dashboard access
No roleSigns in to your app, but has no dashboard access

Everyone can manage their own account, password, two-factor devices and sessions, whatever their role.

Custom roles for your product

In the dashboardAccess Control & Roles›Roles›Create a role
  1. Name the role

    Use a short, stable name your code will check, like billing_manager.

  2. List what it allows

    One permission per line, written as resource:action:scope, for example invoices:read:tenant. These describe the role for your team; your app decides what to enforce.

Then check the role in your app using the roles claim in the user's access token:

Check a role in your API
// After verifying the access token
if (!claims.roles.includes('billing_manager')) {
  return res.status(403).json({ error: 'Billing access required' })
}
TrustPort enforces the built-in roles. Custom roles are carried for you to enforce in your product. They can't unlock anything in the TrustPort dashboard.

Give someone a role

In the dashboardAccess Control & Roles›User access
  1. Find the user

    Search by email or username.

  2. Pick a role and, optionally, an end date

    Set an expiry for temporary access, like a contractor's project or an on-call week. The role stops applying on its own when the date passes.

The change applies the next time their token is refreshed, within 15 minutes. To apply it straight away, ask them to sign out and back in.

Assign a role with the API
curl -X POST https://id.trustportidentity.com/api/v1/roles/assign \
  -H "Authorization: Bearer $TRUSTPORT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "user_id": "<user-id>", "role_name": "billing_manager", "expires_at": "2026-12-31T23:59:59Z" }'

Groups

In the dashboardAccess Control & Roles›Groups

Groups collect people you manage together, such as finance-team. Create a group, then add or remove members from it. Groups are also where people from a customer's directory will land once Directory Sync arrives.

Ask for access instead of granting it

For sensitive roles, let people request access and have someone else approve it. See Access requests and reviews.

© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.