Overview of RBAC
The Ditto portal provides the ability to create, modify, and delete custom roles, allowing you to set fine-grained read-write access controls to database data. With this you can define organization hierarchies for permissions delegation, set permissions for portal functionality like viewing collections, querying tokens, transferring databases between organizations, and more.Organization Permissions Settings
When configuring access control for roles within an organization, there are various types of privileges you can choose from. These can be accessed from the role editor, available under Settings > Roles. The following table provides an overview of the various settings you can configure for roles within an organization.Some permissions have dependencies on others.For example, a role with Accept incoming database transfer requests permission will also have View incoming database transfer requests.Where this applies, these dependent roles will be selected automatically for you when selecting in the role editor.
Database Permissions Settings
Following is an overview of the various settings that, once assigned, grant end users the ability to manage the database. (See Creating Roles)Offline License Token Permissions
The Database Permissions Settings table above includes two permissions related to offline license tokens:- Access offline-only licenses — Grants visibility to the offline license token section on the Connect tab of a database. Users without this permission will not see offline license tokens in the Portal at all.
- Request offline-only licenses — Allows creating and managing offline license tokens. This permission depends on Access offline-only licenses (both are required to create tokens).
If you need offline license tokens but lack the required permissions, ask your organization admin to assign a role with these permissions, or contact Ditto support to have tokens generated for you. For more on obtaining tokens, see Getting SDK Connection Details.
Organization Roles
To establish role-based access controls for your organization:1
Create new roles with the desired settings. (Creating New Roles)
2
Designate roles for the appropriate end users within your organization. (Assigning Roles to End Users)
Creating New Roles
To add a new role to your organization:1
From your organization, click Settings.
2
Click Roles.
3
Click Add new role.

4
Click to select and deselect the settings you want to apply to your new role as desired, and then click Create role.

Assigning Roles to End Users
Once you’ve created a role, designate them to the appropriate end users within your organization:1
From Settings > Members, click Invite member located on the right.

2
From the Invite users modal that appears:
- Enter the email belonging to the end user you want to add.
- Click Role and select the role type you want to assign.
- Click Add to list.
- When finished adding end users to the invite, click Invite users.

Viewing Pending Member Invitations
Once a member is assigned a role, Ditto automatically sends a formal invitation to the email address specified in the invite, which must be accepted before RBAC privileges take effect. To view a list of invitations waiting for approval, go to Settings > Members in the portal. A complete list of invitations display within Pending member invitations, as shown in the following graphic:
Modifying and Deleting Roles
To edit a role’s settings or permanently remove a role from your organization:1
From your organization, click Settings.
2
Click Roles.
3
Click the three-dot menu next to the role you want to modify or delete:
- To modify, select Edit.
- To permanently remove, select Delete.

Ditto Employee Access Grants
There are circumstances in which Ditto’s support team requires elevated privileges to access your database data, for instance, to troubleshoot an issue. Ditto employees can only access your database data with an approved access grant. An access grant is a formal authorization provided by any of the following to approve the access request initiated by Ditto:- Current organization owner
- Organization roles configured with** Manage access grants** privileges
Granting Access
To approve a Ditto-initiated access grant:1
Click Database.
2
From Access grants, click Accept.

Revoking Access
Once an access grant is approved, you can end access at any time:1
Click Database.
2
From Access grants, click Revoke access.
