On This Page

Home / Identity and Access Management/ Access Control/ Permissions Model/Members and Teams

Members and Teams

Control access to Cribl products by inviting and managing Members and creating Teams.


Members are individual users who can access your Cribl deployment. You can assign Permissions to Members and Teams, which are groups that you can add Members to.

Deployment-Level Members

The deployment level differs for Cribl.Cloud and on-prem deployments. On Cribl.Cloud, the Organization is the deployment level. In on-prem deployments, the Workspace is the deployment level.

To access deployment-level Members as an Admin:

Cribl.CloudOn-Prem Deployment

Assign Deployment-Level Permissions

If you’re using SSO, assign deployment-level Permissions by managing group memberships within your identity provider (IdP). Make sure that your IdP group names match the core patterns for automatic Permission mapping. Permissions assigned by IdP group memberships override any Permissions that you set manually on a per-Member or per-Team basis.

If you’re using direct user login, assign deployment-level Permissions to individual Members when you invite or add them to your Organization (Cribl.Cloud) or Workspace (on-prem). You can also update Members’ deployment-level Permissions after they join.

Owners and Organization Registration (Cribl.Cloud)

On Cribl.Cloud, each Member can have Owner Permissions for multiple Organizations, and each Organization can have multiple Members with the Owner Permission. However, each Member (as defined by their email address) can register only one active Organization, and only if they are not already the Owner of a different Organization.

Invite or Add Members

To invite or add new Members at the deployment level:

Cribl.CloudOn-Prem Deployment

Manage Cribl.Cloud Invitations

While an invitation to a Cribl.Cloud Organization is pending, the the Action column on the Members & Teams page offers the following options for handling common issues:

  • Resend Invite: If your invited Member didn’t receive your invitation email, resend it. Invitations expire after seven days if they are not accepted nor revoked and must be resent.
  • Copy Invite Link: If emails aren’t getting through at all, copy and share a URL that will take the invitee directly to the signup page. This target page encapsulates the same identity, Organization or Workspace, and Permission that you specified in the original email invitation.
  • Revoke Invite: Select to revoke a pending invitation. Common reasons to revoke an invitation are sending someone a duplicate invitation and an invitee who spends too much time in space to be a productive collaborator, etc.) After revoking an invitation, you’ll see a confirmation dialog.
Managing Invites
Managing Invites

View Workspace Members on Cribl.Cloud

On Cribl.Cloud, you can view a Workspace’s existing Members at Settings > Product (Stream or Edge) > Members and Teams.

Remove Members

To remove a Member from your deployment:

Cribl.CloudOn-Prem Deployment

Remove SSO Members

If your Cribl.Cloud Organization uses SSO, the identity provider (IdP) admin manages Members in the IdP system. When you remove a Member in the IdP, they are still listed as a Member on Cribl.Cloud.

After removing the Member in the IdP, you must also manually remove them on Cribl.Cloud to completely remove their access.

Assign Worker Group- and Edge Fleet-Level Permissions

Worker Group- and Edge Fleet-level Permissions are available only in on-prem deployments. On Cribl.Cloud, use Product-level Permissions to manage access at the Worker Group/Edge Fleet level.

To assign Permissions on a Worker Group/Edge Fleet in an on-prem deployment:

  1. Make sure that the Member has a Global Permission sufficient to support the access rights that you want to assign on the Worker Group or Edge Fleet.
  2. In the sidebar, select Settings, then Stream/Edge, then Members and Teams.
  3. Select each applicable Member row to open their Member Details drawer.
  4. Grant the Member the desired Permission on the Worker Group or Edge Fleet.

Teams

Teams are groups of Members who share the same Organization, Workspace, and product-level Permissions. Use Teams to efficiently manage access control by assigning Permissions to the Team rather than configuring Permissions each Member individually.

Teams are available only on Cribl.Cloud and in Distributed deployments.

Create a Team

To create and configure a Team:

Cribl.CloudOn-Prem Deployment