1. Docs
  2. Your responsibility

Your responsibility

Signing in to the Admin Workspace opens one screen that answers two questions: what part of the organization you look after, and what you may do there. This page explains how to read it.

Overview

Administrators do not all have the same authority, and the Workspace does not pretend otherwise. Instead of a menu that looks identical for everyone and refuses you halfway through, the first screen states your authority plainly, including the parts you do not have. Everything else in the Workspace follows from what it says.

An action you do not hold is absent, not greyed out. If you cannot find a button, you do not hold the capability behind it.

Where you administer

Your authority is attached to somewhere. That somewhere is either specific places inside an environment, or the environment as a whole.

Assigned to places: your authority covers those places and everything beneath them. Nothing above them, and nothing in a place alongside them.Environment-wide: your authority covers the whole environment, including places someone creates later.More than one environment: each is separate. Switch between them at the top of the screen, and read the answer again, because it can differ.

What you may do

Underneath where, the screen lists what: the capabilities your assignment grants you in the environment you are looking at. This list is the whole of your operational authority there. Nothing in the Workspace offers you an action that is not on it.

If you need something that is not listed, an account administrator grants it by changing your role. You cannot grant it to yourself.

Across the account

Some authority belongs to the account rather than to any one environment: billing, the administrator roster, the account-wide identity directory, account settings. It comes from an account-scoped administrator role, never from an assignment to a place, and it applies in every environment at once.

If you hold none of it, the screen says so rather than leaving the space blank. That is a complete answer, not a loading state.

A role carries capabilities of one kind or the other, never both. Someone who administers people in one place and also pays the bill holds two roles.

The doors you are offered

The last part of the screen is the way onward: the surfaces you can actually open, split into what is available in this environment and what is available across the account. It is built from the same answer as everything above it, so a door you cannot use is not shown.

Next Step

The capability list is the vocabulary the whole Workspace is built on. What administrators can do names every one of them, what it lets you do, and where it stops.

Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.