Administration

Manage users, groups, roles, and access control

users:read

User Management

View all users, manage group assignments, and control user access

users:read

Group Management

Create groups, assign roles, and map to Google Workspace groups

users:read

Roles & Permissions

View role definitions, permission mappings, and access control matrix

Documentation

RBAC System Overview

The Nexus Dashboard uses a hybrid RBAC (Role-Based Access Control) system:

  • Google Workspace Groups - Source of truth for group membership
  • Cloudflare Access - Authentication and group claims in JWT
  • D1 Database - Fine-grained permissions and role mappings
  • Auto-provisioning - Users created on first login

Default Roles

Viewer

Read-only access to dashboards

Operator

Submit and monitor jobs

Admin

Full configuration access

Superadmin

User and role management