Roles & permissions

Ten human roles. Five autonomous agents. One auditable permission model.

Glimmora Forge ships with role definitions tuned for enterprise reality. Every role has scoped data, a tailored home, and a permission set that maps cleanly onto RBAC + ABAC. Pick yours during signup or assign per teammate.

Human roles

Ten roles for ten jobs.

10 roles

Workspace Admin

Admin

Owns workspace, billing, identity, and agent autonomy policy.

e.g. Kavi · Workspace Owner

Configure SSO, RBAC, integrations, agent autonomy levels, and billing. Full read/write across all modules with audit trail visibility.

Scopes
SettingsMembers & RolesIntegrationsAudit
Key permissions
workspace.managemembers.managebilling.manageagents.policyaudit.read
Home dashboard
/dashboard
Hero KPIs

Agents online · Audit events · Active integrations

IT Operations Manager

IT Ops

Runs ITSM, ITOM and ITAM. Sees every service ticket and SLA.

e.g. Aisha Kapoor · IT Ops Lead

Owns the service desk, infrastructure monitoring, and asset lifecycle. Approves changes, drives MTTR, and keeps SLAs healthy.

Scopes
ITSMITOMITAMKnowledge Graph
Key permissions
tickets.*incidents.*changes.approveassets.*slo.read
Home dashboard
/itsm
Hero KPIs

Open incidents · MTTR · SLA breaches

Engineering Lead

Eng Lead

Drives velocity, quality and DORA across engineering teams.

e.g. Priya Shah · Engineering Director

Plans cycles, balances workload, manages on-call rotation, and reviews release risk. Has analytics-first home with AI narrative reports.

Scopes
SprintsDevOpsAnalyticsWorkflows
Key permissions
sprints.manageissues.*deploys.readanalytics.readworkflows.manage
Home dashboard
/analytics
Hero KPIs

Velocity · Cycle time · Change failure rate

Engineer / Developer

Engineer

Ships code, fixes bugs, owns issues and pull requests.

e.g. Marcus Lin · Senior Engineer

Lives in the sprint board and DevOps surfaces. AI suggests fixes, predicts review delays, and auto-creates issues from production errors.

Scopes
SprintsDevOpsTicketsCode Intelligence
Key permissions
issues.assigned.*issues.createpr.reviewdeploys.trigger:nonprod
Home dashboard
/sprints
Hero KPIs

My open issues · PRs in review · My on-call

SRE / On-call

SRE

First responder for production. Lives in monitoring + incidents.

e.g. Jonas Weber · Senior SRE

Owns SLOs, error budgets, and runbooks. AI co-pilots root-cause analysis and auto-runs approved remediation playbooks.

Scopes
MonitoringIncidentsWorkflowsDevOps
Key permissions
incidents.declarerunbooks.executedeploys.rollback:prodalerts.manage
Home dashboard
/monitoring
Hero KPIs

P1/P2 incidents · Error budget burn · Pages this week

Security & GRC Officer

Security

Risk register, compliance, audit evidence, and agent governance.

e.g. Lena Park · CISO

Reviews agent decisions, evidences SOC 2 / ISO controls, manages access reviews. Has a dedicated GRC workspace with auto-generated evidence.

Scopes
GRCAuditSettings:SecurityKnowledge Graph
Key permissions
risk.*audit.readevidence.collectagents.auditaccess.review
Home dashboard
/dashboard
Hero KPIs

Open risks · Controls due · Agent decisions to review

HR Operations

HR Ops

Onboarding, offboarding, policy, and HR self-service.

e.g. Rohan Mehta · HR Operations

Owns the HRSD module. AI assistant handles FAQs and the onboarding agent provisions tooling access from HRIS hire events.

Scopes
HRSDTicketsWorkflows
Key permissions
hrsd.*people.readonboarding.runpolicies.manage
Home dashboard
/itsm
Hero KPIs

New hires this week · Offboarding due · Policy queries

Customer Service Agent

CSM

Omnichannel inbox, case lifecycle, AI-drafted replies.

e.g. Sophia Reyes · CX Lead

Handles chat, email, and voice cases. AI drafts first-pass responses, suggests next-best-action, and keeps SLAs in sight.

Scopes
CSMTicketsKnowledge Graph
Key permissions
cases.*responses.draftkb.readcustomer.read
Home dashboard
/itsm
Hero KPIs

Open cases · CSAT · Avg response time

Business Owner / Executive

Executive

Read-only KPI dashboards, AI narrative reports, board-ready exports.

e.g. Tara Nair · COO

Curated cross-functional dashboards. Forge generates narrative summaries: what shipped, what's at risk, what changed week-over-week.

Scopes
AnalyticsDashboardsReports
Key permissions
analytics.readdashboards.readreports.export
Home dashboard
/analytics
Hero KPIs

Reliability · Revenue at risk · Engineering output

Auditor / Viewer

Viewer

Read-only access for external auditors and stakeholders.

e.g. External · audit firm

No write actions. Sees the same operational truth as your team during audits, reviews, or vendor diligence.

Scopes
Read-only across all modules
Key permissions
*.read
Home dashboard
/dashboard
Hero KPIs

Last audit export · Open evidence requests

Autonomous agents

Five agents that act on your stack.

Non-human roles with policy-bound authority. Every action is audited, citable, and reversible.

5 agents

Triage Agent

ITSM · CSM

Classify and route incoming tickets

Default policy

Autonomous · routes by skill + load

Resolution Agent

Incidents · Runbooks

Execute approved remediation playbooks

Default policy

Auto for ≤ P3 · approval for P1/P2

Code Reviewer

DevOps · Code

Post review comments and suggestions on PRs

Default policy

Suggest only · never blocks merge

Deploy Agent

DevOps · Releases

Initiate canary, rollback, or deploy retries

Default policy

Autonomous in non-prod · approval in prod

Onboarding Agent

HRSD · Identity

Provision tooling access on HRIS hire events

Default policy

Autonomous · audited

Permission matrix

Who can do what.

Boiled down to the actions that matter most. Every cell maps to a granular RBAC + ABAC rule under the hood.

Capability
Admin
IT Ops
Eng Lead
Engineer
SRE
Security
HR Ops
CSM
Executive
Viewer
Manage workspace settings
Manage members & roles
Configure agent autonomy
View audit log
Create / resolve tickets
Approve change requests
Declare incidents
Run runbooks (auto-remediation)
Manage sprints & issues
Trigger production deploys
Roll back production
Manage workflows / agents
View analytics dashboards
Manage GRC & risk register
HR onboarding / offboarding
Customer cases & CSAT
Export data / reports
FullApproveReadNone

Ready to assign roles to your team?

Start free with any role. Upgrade anytime to unlock SAML SSO, SCIM provisioning, and custom RBAC.