Roles and permissions
Selfmade Ninja Labs uses role-based access control (RBAC). What you can do with something depends on a few separate questions, and each one is answered by a different kind of role. This page puts all of them in one place.
An action is allowed only when every question says yes. An AI assistant connected through MCP goes through exactly the same checks as you do in the browser. It never gets more than your account has.
At a glance
| Layer | Roles | Decides | Who sets it |
|---|---|---|---|
| Platform role | User, Moderator, Faculty, Administrator | Access to moderation, the Faculty Panel or the Admin Panel | Platform administrators |
| Plan | Free, Pro | How much you can run, and which features you get | Your subscription, or an administrator |
| Ownership | Owner | Full control of what you created | Automatic |
| Sharing role | Viewer, Deployer, Editor, Manager (templates) · Viewer, Operator, Manager (labs) · Use (VPN interfaces) | What someone you shared with can do | The owner, or a manager |
| Organization role | Owner, Admin, Member | What you can do in an organization or department and with what it owns | Organization owner and admins |
| Community role | Clan owner, admin and member · Club owner, mod and member | Running a clan or club | Clan or club owner |
| Connection | Browser session, MCP client | Nothing extra: MCP inherits everything above | You, when you connect a client |
Platform roles
| Role | What it adds | How someone gets it |
|---|---|---|
| User | Everyone starts here. Your own labs, devices, domains, services and storage, within your plan | Signing in |
| Moderator | The Review queue (shield icon in the top bar) for reported content. Can hide or delete any question, answer or comment, and edit any club's blurb. No Admin Panel | An administrator switches on Platform moderator for the account |
| Faculty | A Faculty Panel in the account menu, with teaching tools: their own cohorts, proof evaluation and accreditation evidence | An administrator sets the account's role to Faculty (Education module only) |
| Administrator | The whole Admin Panel, Global Stats, and access to every account's resources for support. Always counts as a moderator | An administrator grants Admin access — see below |
There are no partial admin roles. An administrator can use every page of the Admin Panel. Grant it only to people who run the platform. For teaching, use Faculty. For community care, use Moderator.
How someone becomes an administrator
There are two independent grants, and either one is enough:
- Local platform admin: a switch on the account, on this platform only.
- Membership of the administrators group at the sign-in provider (for example a GitLab group, or an Okta, Entra ID or Keycloak group the platform is configured to trust). Leave the group, and admin rights end at the next sign-in.
Both take effect at the person's next sign-in. The Role label on a user's page (User, Faculty, Admin) is only a label, and choosing "Admin" there does not grant admin rights. Use the Admin access card instead. Step by step: Admin guide → Users.
Safeguards:
- You cannot switch off your own platform-admin setting when it is your only route to admin rights. The platform refuses and asks another administrator to do it.
- Removing admin rights applies at the person's next sign-in. To end their admin access straight away, also block or deactivate the account, which signs them out everywhere.
- Granting and revoking admin, and changing someone's role, are recorded in the audit log.
What administrators can see
Administrators can open any account's labs and resources to help with support, and can impersonate a user to see exactly what that user sees. Impersonation requires the administrator to have signed in recently, and every start and end is recorded with who did it, when, and the reason if one was given. See Impersonation.
Plans
Your plan sets how much, not who. These are the platform defaults. Your own numbers are always in Account Settings → Account Limits, because an administrator can raise or lower them for your account.
| Free | Pro | |
|---|---|---|
| Labs running at once | 2 | 4 |
| Home storage | 2.5 GB | 25 GB |
| Database and broker users | 2 | 15 |
| Lab catalogue | Free labs | All labs |
| Your own domain names | — | Up to 25 |
| Extra TCP ports on a lab | After earning 5,000 Zeal | Yes |
| Scale groups (autoscaling) | — | Yes |
| Always-on labs | After earning 5,000 Zeal | Yes |
| Sharing labs and templates | After earning 7,500 Zeal | Yes |
| Devices, names on the platform's domains | 5 each | 5 each |
More in Plans and limits.
Owning something
Whoever creates a lab, template, domain, device, network or service owns it. The owner can always do everything with it, including the things no shared role allows:
- Terminate a running lab (unless the owner hands that one permission out).
- Transfer a template to someone else.
- Give someone the Manager role.
Something created while acting as an organization is owned by the organization, not by you.
Sharing roles
When you share a template or a running lab, you choose a role for the person or group you share it with. Higher roles include everything below them.
Templates
| Role | Can |
|---|---|
| Viewer | See the template and its details. Can't deploy or change anything |
| Deployer (default) | Deploy their own copies. Can't edit it |
| Editor | Edit files, configuration and builds. Can't manage sharing |
| Manager | Everything an editor can, plus manage who it is shared with |
Running labs
| Role | Can |
|---|---|
| Viewer (default) | Watch the lab and open its app (Launch). Can't stop, redeploy or change anything |
| Operator | Start, stop, pause and redeploy it |
| Manager | Everything an operator can, plus preferences, sharing and VS Code / terminal. Only the owner can terminate it |
VPN interfaces
A shared private network has one role, Use: the person can attach their labs and devices to it. See Private networks.
Extras: one permission without the whole role
A share can carry extras that grant a single action without raising the role:
| Extra | Allows | Who can grant it |
|---|---|---|
| VS Code / terminal | A real shell inside the lab, to someone below Manager | Owner only |
| Open the app (Launch) | The lab's web interface | Owner or manager, or someone who can re-share and holds it |
| Stop | Shut the copy down | Owner or manager, or someone who can re-share and holds it |
| Redeploy | Rebuild the copy from its template | Owner or manager, or someone who can re-share and holds it |
| Terminate | Destroy the copy | Owner only |
| Can re-share | Pass the access on, at or below their own role | Owner or manager |
A shell comes with the Manager role, or with the VS Code / terminal extra. Anyone with it can read and change every file in the lab and in your shared home storage. Give it only to people you would give your password to.
Sharing with groups
You can share with a person, a workgroup, an organization or a department. A group share can apply to All members or only to Owners & admins. For something an organization owns, sharing never reaches outside that organization. Only its members can ever use it.
The platform policy
Administrators set the minimum role each action needs, platform-wide. Owners and administrators always pass, and an extra still works below the minimum. See Access control → Policy.
Everything about sharing, including how to share and revoke access, is in Sharing and workgroups and Share and publish templates.
Organizations and departments
| Role | Can |
|---|---|
| Owner (one person) | Everything an admin can, plus transfer a member's entitlements and request deletion. Cannot be removed or have their role changed; ownership moves only through a platform administrator |
| Admin | Edit the profile; add, remove and promote members; create departments; set department limits |
| Member | Use everything the organization owns, including VS Code / terminal, preferences and sharing on its labs; switch to acting as it; and leave |
Rules worth knowing:
- Only platform administrators create organizations. Organization owners and admins create departments.
- A department's limits are carved from the organization's and can never add up to more.
- Any member can do everything with the organization's labs, including opening a terminal in them. Only the organization's owner or admins can terminate them. Add only people you trust with every lab the organization owns.
- Transferring a template keeps the previous owner on it as a Manager, unless you choose otherwise.
- If you belong to a department, you act as that department rather than the whole organization (unless you are an owner or admin of the organization).
Details: Members and roles and Acting as an organization.
Clans and clubs
| Owner | Admin / Mod | Member | |
|---|---|---|---|
| Clan | Invite, remove admins, close requests, delete the clan. Cannot leave; can only delete | Accept requests, edit details, remove and promote members, delete chat messages | Play, chat, delete their own messages, and use the clan's labs (including a terminal) |
| Club | Promote, transfer ownership, archive. Must transfer before leaving | Invite and remove members; hide posts | Post (if the club allows it) |
A club decides who may post: Everyone, Mods & Admins only, or admins only. Creating a club needs 1,000 Zeal and costs 100 Jolt. See Clans and clubs.
Moderating discussions
| Who | Hide | Delete |
|---|---|---|
| Platform administrators and moderators | Anywhere | Anywhere |
| Club owner | In their club | In their club |
| Club mod | In their club | — |
Hide is reversible. Delete is final, needs a reason, and tells the author.
Through an AI assistant (MCP)
Connecting an AI assistant does not create a new role. The assistant signs in as you, and every tool call goes through the same checks as the dashboard:
- It sees only what you own, what is shared with you, and what your organizations own.
- A shared role limits it the same way. For example, a Viewer's assistant cannot stop a lab.
- Your plan limits it the same way. For example, a Free account's assistant can read but not deploy.
- Administrator tools appear only for administrators.
How the connection is secured is explained in How MCP connections are secured.
Who sets what
| To change… | Ask |
|---|---|
| Your plan or limits | A platform administrator |
| Someone's role on your lab or template | You (owner) or a manager of it |
| A member's role in an organization | The organization's owner or an admin |
| Moderator, Faculty or Administrator | A platform administrator |
| The minimum role for an action | A platform administrator (Access Control → Policy) |