November 17th, 2025
As always, when you ask for things, we listen. We are happy to announce that you can now assign the Space Admin role to users for non-root spaces! Non-root Space Admins can now view all roles, users, API keys, IdP group mappings (read-only), and manage role bindings within their assigned administered spaces. Previously, these capabilities were limited to Root Space Admins only. This is a big step forward to help better enable multi-tenancy administration inside the Spacelift platform.

Root Space Admins (Space Admin role on the root space) have account-wide privileges including:
All Space Admin permissions across all spaces
SSO setup, VCS configuration, audit trail management
Invite/revoke users and create/modify/delete roles
Create/modify/delete API keys and IdP group mappings
Manage role bindings across all spaces
Non-root Space Admins (Space Admin role on any non-root space) have limited privileges:
Space Admin permissions only within the spaces they administer
Can view all roles, users, API keys, and IdP group mappings
Can manage role bindings only for the spaces they administer
Cannot invite/revoke users, create/modify/delete roles, or create/modify/delete API keys and IdP group mappings
For more information on the Space Admin role, check out the documentation here!