Understand Oplane’s layered access model: organisation roles (Org Admin, Org Member), workspace membership, and inherited threat model permissions.
Oplane uses a layered access model. Permissions are determined by your organisation role and workspace membership, with threat model access inherited from the workspaces they belong to.
Every user belongs to an organisation with one of these roles:
Role
Description
Org Member
Standard organisation member. Can view the organisation, access analytics, and work within assigned workspaces.
Org Admin
Organisation administrator. Can manage members, update org settings, manage personal access tokens, manage security rules, and access all non-personal workspaces.
Access to threat models is inherited from workspaces. If you can access any workspace that contains a threat model, you can view and update it. Security requirements inherit access from their parent threat model.
A threat model can belong to multiple workspaces. A user only needs access to one of those workspaces to view and edit the threat model.