Every identity in your Nuon org — whether a team member or a service account — must be assigned a role. The role determines what that identity can read and change in the org.
Roles are org-scoped: a role assigned in one org grants no access in any other org.
Available roles
Assigning roles
The same role set applies everywhere an identity is created. You choose a role when you:
API tokens and OIDC trust policies are each backed by a dedicated service account that carries the role — so a token or an exchanged token acts as that service account, with exactly the access its role grants.
An identity holds one role at a time; assigning a new role replaces the old one.
Permission errors
When an identity attempts something its role does not allow, Nuon returns a message describing the access the action requires and the role you currently hold — for example, “this action requires write access to installs in this organization.” Ask an org admin to assign a role that grants the needed access.
Reserved roles
The Runner role is reserved for the machine accounts Nuon provisions for your runners. It is assigned automatically and is never user-selectable.