16.3 Global Permissions

Orbnetes deployment and release orchestration documentation for operators and platform teams.

Global permissions apply platform-wide and should be limited to trusted administrators.

Typical global privileges:

  • super-admin / full platform control,
  • global secrets management,
  • global variables management,
  • system-level config (oauth/notifications/integration settings).

Why separate global from project scope:

  • prevents project operators from changing platform-wide security posture,
  • preserves blast-radius control,
  • simplifies governance and incident ownership.

Best practices:

  • keep number of global admins small,
  • use dedicated admin accounts where possible,
  • enforce stronger security controls (2FA) for global-privileged users.