Manage permissions
You can grant organization users, application users, and groups access at the organization and project level through roles and permissions.
When you remove permissions from a user or group, service credentials are not changed. Users can still directly access services if they know the service credentials. To prevent this type of access, reset all service passwords.
Organization permissions
Grant organization permissions to a user or group
- Console
- Terraform
- 
In the organization, click Admin. 
- 
Click Permissions. 
- 
Click Grant permissions and select Grant to users or Grant to groups. 
- 
Select the users or groups, and the roles and permissions to grant. 
- 
Click Grant permissions. 
Use the aiven_organization_permission resource
and set the resource_type to organization.
Change organization permissions for a user or group
- 
In the organization, click Admin. 
- 
Click Permissions. 
- 
For the user or group click Actions > Edit permissions. 
- 
Add or remove permissions and click Save changes. 
Remove all organization-level roles and permissions
You can remove all organization-level permissions that you granted to a user or group. After removing the permissions, organization users have the default access level to the organization.
To remove all organization permissions for a user or group:
- 
In the organization, click Admin. 
- 
Click Permissions. 
- 
For the user or group click Actions > Remove. 
- 
Click Remove user or Remove group to confirm. 
Make users super admin
The super admin role is a special role that has unrestricted access to an organization and all its resources and settings.
You cannot make application users super admin.
This role should be limited to as few users as possible for organization setup and emergency use. For daily administrative tasks, assign users the organization admin role instead. Aiven also highly recommends enabling two-factor authentication for super admin.
- In the organization, click Admin.
- Click Users.
- Find the user and click Actions > Make super admin.
To revoke super admin privileges for a user, follow the same steps and select Revoke super admin.
Project permissions
You can give users access to a specific project by granting them roles and permissions at the project level.
Grant project permissions to a user or group
- Console
- Terraform
- 
In the project, click Permissions. 
- 
Click Grant permissions and select Grant to users or Grant to groups. 
- 
Select the users or groups to add to the project. 
- 
Select the roles and permissions to grant. 
- 
Click Grant permissions. 
Use the aiven_organization_permission resource
and set the resource_type to project.
Change permissions for a user or group
- 
In the project, click Permissions. 
- 
For the user or group click Actions > Edit permissions. 
- 
Add or remove permissions and click Save changes. 
Remove all project-level roles and permissions
To remove all permissions to a project:
- 
In the project, click Permissions. 
- 
For the user or group click Actions > Remove. 
- 
Click Remove user or Remove group to confirm.