Reference

Roles and Responsibilities

Workspace roles, access scope, resource assignments, and session records in Cerberus.

Page type: ReferenceRolesStatus: CurrentCurrent product behaviorLast reviewed: 2026-07-27

Cerberus roles define which resources and management areas a person can use inside a workspace. A role is not a standalone session key; it works together with resource assignment, duration, readiness state, and session policy.

This page summarizes the product responsibilities of each visible workspace role.

Scope

Role scope is used with:

  • person identity,
  • workspace scope,
  • role and responsibility,
  • resource state,
  • explicit assignment,
  • active duration or policy,
  • local account and credential readiness,
  • active session, revocation, or closure state.

Together, these inputs determine which resources a person can see, which sessions they can start, and which records they can review.

Role Types

Roles fall into three main usage areas:

  • Administration roles: manage people, resources, assignments, policies, billing, and security settings.
  • Work roles: perform maintenance, support, or daily operations on assigned resources.
  • Review roles: provide visibility into state, sessions, revocation, and records.

Role Outcomes

This table maps role names to user-visible product outcomes. Resource assignment, duration, readiness, and session policy are still evaluated for every launch decision.

Role Resources and sessions Team and access management Record visibility Commercial area
Workspace owner Manages resources and can close their own sessions or active sessions across the workspace. Manages people, invitations, roles, and assignments. Reviews session and access records and can use export capabilities. Manages plan, invoice, payment, and usage records.
Workspace admin Manages resources and can close their own sessions or active sessions across the workspace. Manages people, invitations, roles, and assignments. Reviews session and access records. Commercial management uses the workspace owner or billing admin role.
Operator Opens assigned resources and closes their own active sessions. Assignment and role changes use management roles. Reviews the session and access records needed for operations. Commercial visibility uses the relevant commercial role.
Viewer Uses read-only resource and session visibility. Uses read-only visibility for team and access decisions. Reviews records within the visible scope. Can view plan and usage summaries.
Billing admin Views Agent inventory for commercial support. Team and access management uses workspace roles. Works with support-ticket context. Manages plan, invoice, payment, and usage records.
Remote access user Opens assigned resources and closes their own sessions. Team, role, and assignment management uses workspace roles. Sees their own session context. Commercial management uses the relevant commercial roles.

Access Areas

Role scope is used across:

  • resource inventory and readiness state,
  • person and invitation management,
  • assignment and time-bound access records,
  • session launch and active session views,
  • revocation, closure, and evidence records,
  • billing, plan, and usage records.

Records

Role and access records show:

  • the person’s workspace context,
  • role and responsibility,
  • resource assignment,
  • session start,
  • closure or revocation event,
  • review time and record context.

These records show which role a person used, which resource was involved, and which session scope shaped the work.