Skip to main content
Every identity in your Nuon org — whether a team member or a service account — must be assigned a role. The role determines what that identity can read and change in the org. Roles are org-scoped: a role assigned in one org grants no access in any other org.

Available roles

Assigning roles

The same role set applies everywhere an identity is created. You choose a role when you: API tokens and OIDC trust policies are each backed by a dedicated service account that carries the role — so a token or an exchanged token acts as that service account, with exactly the access its role grants.
An identity holds one role at a time; assigning a new role replaces the old one.

Permission errors

When an identity attempts something its role does not allow, Nuon returns a message describing the access the action requires and the role you currently hold — for example, “this action requires write access to installs in this organization.” Ask an org admin to assign a role that grants the needed access.

Reserved roles

The Runner role is reserved for the machine accounts Nuon provisions for your runners. It is assigned automatically and is never user-selectable.