Skip to main content

Roles and permissions

Selfmade Ninja Labs uses role-based access control (RBAC). What you can do with something depends on a few separate questions, and each one is answered by a different kind of role. This page puts all of them in one place.

An action is allowed only when every question says yes. An AI assistant connected through MCP goes through exactly the same checks as you do in the browser. It never gets more than your account has.

At a glance

LayerRolesDecidesWho sets it
Platform roleUser, Moderator, Faculty, AdministratorAccess to moderation, the Faculty Panel or the Admin PanelPlatform administrators
PlanFree, ProHow much you can run, and which features you getYour subscription, or an administrator
OwnershipOwnerFull control of what you createdAutomatic
Sharing roleViewer, Deployer, Editor, Manager (templates) · Viewer, Operator, Manager (labs) · Use (VPN interfaces)What someone you shared with can doThe owner, or a manager
Organization roleOwner, Admin, MemberWhat you can do in an organization or department and with what it ownsOrganization owner and admins
Community roleClan owner, admin and member · Club owner, mod and memberRunning a clan or clubClan or club owner
ConnectionBrowser session, MCP clientNothing extra: MCP inherits everything aboveYou, when you connect a client

Platform roles

RoleWhat it addsHow someone gets it
UserEveryone starts here. Your own labs, devices, domains, services and storage, within your planSigning in
ModeratorThe Review queue (shield icon in the top bar) for reported content. Can hide or delete any question, answer or comment, and edit any club's blurb. No Admin PanelAn administrator switches on Platform moderator for the account
FacultyA Faculty Panel in the account menu, with teaching tools: their own cohorts, proof evaluation and accreditation evidenceAn administrator sets the account's role to Faculty (Education module only)
AdministratorThe whole Admin Panel, Global Stats, and access to every account's resources for support. Always counts as a moderatorAn administrator grants Admin access — see below
Administrator is all-or-nothing

There are no partial admin roles. An administrator can use every page of the Admin Panel. Grant it only to people who run the platform. For teaching, use Faculty. For community care, use Moderator.

How someone becomes an administrator

There are two independent grants, and either one is enough:

  1. Local platform admin: a switch on the account, on this platform only.
  2. Membership of the administrators group at the sign-in provider (for example a GitLab group, or an Okta, Entra ID or Keycloak group the platform is configured to trust). Leave the group, and admin rights end at the next sign-in.

Both take effect at the person's next sign-in. The Role label on a user's page (User, Faculty, Admin) is only a label, and choosing "Admin" there does not grant admin rights. Use the Admin access card instead. Step by step: Admin guide → Users.

Safeguards:

  • You cannot switch off your own platform-admin setting when it is your only route to admin rights. The platform refuses and asks another administrator to do it.
  • Removing admin rights applies at the person's next sign-in. To end their admin access straight away, also block or deactivate the account, which signs them out everywhere.
  • Granting and revoking admin, and changing someone's role, are recorded in the audit log.

What administrators can see

Administrators can open any account's labs and resources to help with support, and can impersonate a user to see exactly what that user sees. Impersonation requires the administrator to have signed in recently, and every start and end is recorded with who did it, when, and the reason if one was given. See Impersonation.

Plans

Your plan sets how much, not who. These are the platform defaults. Your own numbers are always in Account Settings → Account Limits, because an administrator can raise or lower them for your account.

FreePro
Labs running at once24
Home storage2.5 GB25 GB
Database and broker users215
Lab catalogueFree labsAll labs
Your own domain namesUp to 25
Extra TCP ports on a labAfter earning 5,000 ZealYes
Scale groups (autoscaling)Yes
Always-on labsAfter earning 5,000 ZealYes
Sharing labs and templatesAfter earning 7,500 ZealYes
Devices, names on the platform's domains5 each5 each

More in Plans and limits.

Owning something

Whoever creates a lab, template, domain, device, network or service owns it. The owner can always do everything with it, including the things no shared role allows:

  • Terminate a running lab (unless the owner hands that one permission out).
  • Transfer a template to someone else.
  • Give someone the Manager role.

Something created while acting as an organization is owned by the organization, not by you.

Sharing roles

When you share a template or a running lab, you choose a role for the person or group you share it with. Higher roles include everything below them.

Templates

RoleCan
ViewerSee the template and its details. Can't deploy or change anything
Deployer (default)Deploy their own copies. Can't edit it
EditorEdit files, configuration and builds. Can't manage sharing
ManagerEverything an editor can, plus manage who it is shared with

Running labs

RoleCan
Viewer (default)Watch the lab and open its app (Launch). Can't stop, redeploy or change anything
OperatorStart, stop, pause and redeploy it
ManagerEverything an operator can, plus preferences, sharing and VS Code / terminal. Only the owner can terminate it

VPN interfaces

A shared private network has one role, Use: the person can attach their labs and devices to it. See Private networks.

Extras: one permission without the whole role

A share can carry extras that grant a single action without raising the role:

ExtraAllowsWho can grant it
VS Code / terminalA real shell inside the lab, to someone below ManagerOwner only
Open the app (Launch)The lab's web interfaceOwner or manager, or someone who can re-share and holds it
StopShut the copy downOwner or manager, or someone who can re-share and holds it
RedeployRebuild the copy from its templateOwner or manager, or someone who can re-share and holds it
TerminateDestroy the copyOwner only
Can re-sharePass the access on, at or below their own roleOwner or manager
A terminal is full access

A shell comes with the Manager role, or with the VS Code / terminal extra. Anyone with it can read and change every file in the lab and in your shared home storage. Give it only to people you would give your password to.

Sharing with groups

You can share with a person, a workgroup, an organization or a department. A group share can apply to All members or only to Owners & admins. For something an organization owns, sharing never reaches outside that organization. Only its members can ever use it.

The platform policy

Administrators set the minimum role each action needs, platform-wide. Owners and administrators always pass, and an extra still works below the minimum. See Access control → Policy.

Everything about sharing, including how to share and revoke access, is in Sharing and workgroups and Share and publish templates.

Organizations and departments

RoleCan
Owner (one person)Everything an admin can, plus transfer a member's entitlements and request deletion. Cannot be removed or have their role changed; ownership moves only through a platform administrator
AdminEdit the profile; add, remove and promote members; create departments; set department limits
MemberUse everything the organization owns, including VS Code / terminal, preferences and sharing on its labs; switch to acting as it; and leave

Rules worth knowing:

  • Only platform administrators create organizations. Organization owners and admins create departments.
  • A department's limits are carved from the organization's and can never add up to more.
  • Any member can do everything with the organization's labs, including opening a terminal in them. Only the organization's owner or admins can terminate them. Add only people you trust with every lab the organization owns.
  • Transferring a template keeps the previous owner on it as a Manager, unless you choose otherwise.
  • If you belong to a department, you act as that department rather than the whole organization (unless you are an owner or admin of the organization).

Details: Members and roles and Acting as an organization.

Clans and clubs

OwnerAdmin / ModMember
ClanInvite, remove admins, close requests, delete the clan. Cannot leave; can only deleteAccept requests, edit details, remove and promote members, delete chat messagesPlay, chat, delete their own messages, and use the clan's labs (including a terminal)
ClubPromote, transfer ownership, archive. Must transfer before leavingInvite and remove members; hide postsPost (if the club allows it)

A club decides who may post: Everyone, Mods & Admins only, or admins only. Creating a club needs 1,000 Zeal and costs 100 Jolt. See Clans and clubs.

Moderating discussions

WhoHideDelete
Platform administrators and moderatorsAnywhereAnywhere
Club ownerIn their clubIn their club
Club modIn their club

Hide is reversible. Delete is final, needs a reason, and tells the author.

Through an AI assistant (MCP)

Connecting an AI assistant does not create a new role. The assistant signs in as you, and every tool call goes through the same checks as the dashboard:

  • It sees only what you own, what is shared with you, and what your organizations own.
  • A shared role limits it the same way. For example, a Viewer's assistant cannot stop a lab.
  • Your plan limits it the same way. For example, a Free account's assistant can read but not deploy.
  • Administrator tools appear only for administrators.

How the connection is secured is explained in How MCP connections are secured.

Who sets what

To change…Ask
Your plan or limitsA platform administrator
Someone's role on your lab or templateYou (owner) or a manager of it
A member's role in an organizationThe organization's owner or an admin
Moderator, Faculty or AdministratorA platform administrator
The minimum role for an actionA platform administrator (Access Control → Policy)

Next steps