EpistaBase Docs
Admin

Roles and access

Understand how workspace membership, project membership, and tenant boundaries affect what users can see.

referenceReviewed 2026-06-26

EpistaBase authorization starts with the tenant/workspace boundary and then applies workspace and project membership.

Practical model

LayerWhat it controls
TenantOrganization boundary. Cross-tenant data is not visible.
WorkspaceActive lab/program context and workspace-level access.
ProjectSpecific project membership and editing rights.
Asset grantsDirect access to governed catalog assets where applicable.

Project roles

Project roles typically include owner, editor, commenter, and viewer. Owners can administer project membership. Editors can work on project content. Commenters and viewers have narrower access.

Workspace roles

Workspace roles are broader. The exact names exposed in the product may vary by deployment, but the important distinction is whether a user can administer the workspace, create/edit scientific records, or only read.

Access symptoms

SymptomLikely cause
You can sign in but see no projectWorkspace or project membership is missing.
A search result is absentSearch respects access boundaries.
File opens failCatalog grant, project membership, or workspace policy may block the read.
Provenance is hiddenFeature is disabled for the workspace or unavailable to the user.

On this page