Authentication
Authentication for the user interface is managed using a Keycloak instance. Users are either managed directly in this instance, or using an external identity provider using OpenID Connect or SAML 2.0 (e.g. AzureAD).
The table below lists the available roles and their associated permissions.
| Role | Dashboard | Spaces creation | Space configuration | Submit | Review | Configure org endpoints |
|---|---|---|---|---|---|---|
| super-admin | ||||||
| <org_id>-admin | ||||||
| <org_id>-user | ||||||
| space admin | ||||||
| space submitter | ||||||
| space reviewer | ||||||
| space anonymous submitter |