Default roles
OpenWork Cloud comes with three default roles:Owner: full org control, including member roles and custom roles.Admin: can invite people, manage teams, and manage most shared Cloud resources.Member: can use resources shared with them but cannot manage org administration.
Owner can change member roles, remove members, or create, edit, and delete custom roles.
Invite members
- Open
Members. - On the
MembersorInvitationstab, clickAdd memberorInvite member. - Enter the teammate
Email. - Choose the initial
Role. - Click
Send invite.

SSO just-in-time provisioning
When SSO just-in-time provisioning adds someone to an organization on first sign-in, OpenWork assigns the baselineMember role. IdP attributes such as role, groups, or admin are not used to grant OpenWork organization roles.
Treat Admin, Owner, and custom-role elevation as explicit access changes made inside OpenWork. Review those changes in the member list and audit trail instead of relying on unvalidated IdP attributes for authorization.
Restrict who can join
If you only want teammates from specific companies or domains to join:- Open
Org settings. - Turn on
Restrict allowed email domains. - Add each approved domain to the
Domain allowlist. - Click
Save settings.
Create teams
- Open
Members -> Teams. - Click
Create Team. - Set
Team name. - Choose
Team members. - Click
Create team.
Use custom roles when needed
- Open
Members -> Roles. - Click
Create role. - Enter
Role name. - Choose the permissions that role should have.
- Click
Create role.
security_configuration.manage for the identity/security operator role that manages SSO, SCIM, and organization API keys. Keep it separate from day-to-day Admin membership operations when your organization needs separation of duties.
Practical access pattern
A simple setup that works well for most orgs:- keep 1-2
Ownerusers - give day-to-day operators
Admin - keep most people as
Member - use
Teamsto decide who can see specific marketplaces or providers
Notes
- You cannot change the org owner’s role or remove the owner.
- Owners and admins can manage teams and invitations, but only owners can handle the sensitive RBAC changes.
- Only owners can change
Org settings, including allowed email domains and desktop restrictions. - You cannot delete a custom role while members or pending invitations still use it.