In the same way that group membership is shown as part of approval policies inout data, we would like that the new custom roles are also part of this inout data.
Thanks for explaining your approach, this was an interesting read. Sounds like credential leasing or a kind of vending machine approach if I understand correctly?
Before we proceed further though, can you please clarify what you mean by someone’s “role” in this context? Is this the Spacelift role, so the level of access to the space you’re approving the run for? Or there’s some different meaning here?
Log in to comment and vote
Comments6
Marcin Białoń
Nov 21, 2025
We added the
author_rolesfield to the approval policy’s input data.Lime Fork
Nov 24, 2025
Thanks a lot!
Black Breeze
Oct 15, 2025
Thanks for explaining your approach, this was an interesting read. Sounds like credential leasing or a kind of vending machine approach if I understand correctly?
Before we proceed further though, can you please clarify what you mean by someone’s “role” in this context? Is this the Spacelift role, so the level of access to the space you’re approving the run for? Or there’s some different meaning here?