- Permissions grant ability to perform actions (e.g.,
project:adaptallows fine-tuning) - Roles are named sets of permissions, assignable to users
- Teams are groups with shared access to projects and resources
Common operations
Admin team
The reservedadmin team controls global operations. Some permissions behave differently depending on team membership:
- Any team: list roles, list teams, list/update users in the same team
adminteam only: create roles, create teams, add/remove users from any team
admin team membership to perform global operations.
Seed admins are created once during initial deployment. Add email addresses to admins in values.yaml to bootstrap the first admin users:

