Skip to content

Give a teammate access

A person joins an account by invitation. The invitation is emailed, it expires, and it carries the access they get when they accept, so nobody has to remember to grant anything afterwards.

Terminal window
deployport iam invitations create teammate@company.com --group platform

Both --group and --policy take one name and can be repeated, and the two combine.

A group is the ordinary way to scope somebody. A policy is the escape hatch for the thing no group expresses. Deployport creates a group per machine, so inviting somebody to one machine is inviting them to its group, and the invitation says what it is for without anybody reading a policy.

Naming a policy first makes the rare path look like the intended one. Start with the group.

Terminal window
deployport iam invitations list

An invitation that has not been accepted can be revoked:

Terminal window
deployport iam invitations revoke <invitation-id>

An invitation is for a person. When the identity is a build runner or another program, mint a username inside the account instead:

Terminal window
deployport iam users create build-runner

It has no address and no invitation, and it starts with no permissions. Attach the one policy it needs:

Terminal window
deployport iam users policies attach --username build-runner --policy <policy-name>

Write a policy is the page before this one if the policy does not exist yet.