Skip to content
Warplock

Three roles for your integration partner. Three for you.

Partner roles give your integration partner cross-Client control and support visibility. Client roles give your own people enough control to run routine changes without waiting on us, and no more. Every scoped action happens inside one visible Active Client Context.

Identity, the boring way
  • Built-in accounts with Argon2id password hashing
  • TOTP multi-factor required for integration partner users before any action
  • Login and MFA attempts throttled per account
  • Sessions carry a version; role, membership, password or MFA changes invalidate older sessions
Integration partner

Partner Admin

Partner accounts, platform settings, Clients, Host Execution Credentials and deployments.

Integration partner

Partner Operator

Deployment, runtime host placement and Gateway public ingress, without partner accounts, credentials or Client configuration.

Integration partner

Partner Viewer

Inspect platform and Client operational state without changing it.

Your organisation

Client Admin

Your users, SQL Connections, DAB Instances, entities, tokens, runtimes, Promotion and audit retention.

Your organisation

Client Developer

Everything a Client Admin can configure, except users and Promotion.

Your organisation

Client Viewer

Inspect health, logs, generated configuration and connection details.

What each role can do

Scroll the table sideways for the role columns.

CapabilityPartner AdminPartnerPartner OperatorPartnerPartner ViewerPartnerClient AdminClientClient DeveloperClientClient ViewerClient
Partner accounts and platform settingsManage—View———
Client workspaces and membershipsClient Admins manage their own Client's users.ManageViewViewManage——
SQL Connections, DAB Instances, Exposed EntitiesManageViewViewManageManageView
Draft Change authoringManageViewViewManageManageView
PromotionSubject to Policy Governance approvals.ManageViewViewManageViewView
MCP Access Tokens and Runtime Enrollment TokensManageViewViewManageManageView
Runtime host placement and Gateway public ingressManageManageView———
Host Execution CredentialsNever shown back in plaintext to anyone.Manage—————
Query Audit payload policy and retentionManageViewViewManageViewView
Retained payload contentOnly with the Payload Viewer permission, and for partner users only where the Client allows Partner Payload Access.ViewViewViewViewViewView

Manage means create, edit and the audited lifecycle controls for that record. View means read-only inspection of metadata. Capabilities outside this table follow the same shape: partner roles for platform and infrastructure, Client roles for the Client's own records.

Policy Governance

Your Client can hold approval authority over sensitive policy changes. Where it does, a Promotion waits for that approval. Partner emergency paths exist, and they are recorded separately so they are always visible.

Partner Payload Access

A Client setting that decides whether your integration partner can see retained Query Audit content at all. Metadata stays visible for support; content is yours to grant.

Payload Viewer

A permission, not a role. Retained content is visible only to users who hold it, every view is an Operational Event, and retention state can still make content unavailable.

Need single sign-on?

Built-in accounts are the current posture. Tell your partner what your identity provider needs and where it sits on the roadmap.

Talk to a partner in your area