Skip to main content

Overview

Infisical’s organization permissions system follows a role-based access control (RBAC) model built on a subject-action-object framework. At the organization level, these permissions determine what actions users/machines can perform on various resources across the entire organization. Each permission consists of:
  • Subject: The resource the permission applies to (e.g., project, members, billing)
  • Action: The operation that can be performed (e.g., read, create, edit, delete)
Some organization-level resources—specifically app-connections—support conditional permissions and permission inversion for more granular access control.

Available organization permissions

Below is a comprehensive list of all available organization-level subjects and their supported actions, organized by functional area.

Project management

Subject: project (formerly workspace)

Subject: sub-organization

Role management

Subject: role

User management

Subject: member

Subject: groups

Subject: identity

Security & compliance

Subject: secret-scanning

Subject: settings

Subject: incident-contact

Subject: audit-logs

Subject: email-domains

Identity provider integration

Subject: sso

Subject: scim

Subject: ldap

Subject: github-org-sync

Billing & subscriptions

Subject: billing

Templates & automation

Subject: project-templates

Integrations

Subject: app-connections

Supports conditions and permission inversion

Key management

Subject: kms

Subject: kmip-server

Honey tokens

Subject: honey-tokens

Insights

Subject: secrets-management-insights

Admin tools

Subject: organization-admin-console

Secure share

Subject: secret-share

Gateway management

Subject: gateway

Subject: gateway-pool

Subject: relay

Subject: machine-identity-auth-template