Give a teammate access
A person joins an account by invitation. The invitation is emailed, it expires, and it carries the access they get when they accept, so nobody has to remember to grant anything afterwards.
Invite them
Section titled “Invite them”deployport iam invitations create teammate@company.com --group platformBoth --group and --policy take one name and can be repeated, and the two combine.
Scope it with a group first
Section titled “Scope it with a group first”A group is the ordinary way to scope somebody. A policy is the escape hatch for the thing no group expresses. Deployport creates a group per machine, so inviting somebody to one machine is inviting them to its group, and the invitation says what it is for without anybody reading a policy.
Naming a policy first makes the rare path look like the intended one. Start with the group.
See who has been invited
Section titled “See who has been invited”deployport iam invitations listTake it back
Section titled “Take it back”An invitation that has not been accepted can be revoked:
deployport iam invitations revoke <invitation-id>An identity that is not a person
Section titled “An identity that is not a person”An invitation is for a person. When the identity is a build runner or another program, mint a username inside the account instead:
deployport iam users create build-runnerIt has no address and no invitation, and it starts with no permissions. Attach the one policy it needs:
deployport iam users policies attach --username build-runner --policy <policy-name>Write a policy is the page before this one if the policy does not exist yet.