Rewind uses Role-Based Access Control (RBAC) to manage what each person in your organization can see and do. This article describes each of the six Rewind roles, compares their permissions, and answers common questions about assigning and changing roles.
Covered in this article:
- Role capabilities by permission
- Role descriptions
- Scoping access to a backup configuration
- FAQ
- Related articles
Role capabilities by permission
Organization-wide roles
Organization Owner and Organization Admin apply across your whole organization. They are the only roles that can perform the actions below. They can also perform every action in the scoped roles table, for every integration in your organization, without being assigned to them.
| Action / permission | Organization Owner | Organization Admin |
|---|---|---|
| Manage access | ||
| Add / remove users | ✓ | ✓ |
| Assign / change roles | ✓ | ✓ |
| Transfer organization ownership | ✓ | — |
| Organization settings | ||
| Configure organization settings (including SSO) | ✓ | ✓ |
| Link / unlink integrations | ✓ | ✓ |
| Billing and data | ||
| Manage billing & subscriptions | ✓ | ✓ |
| Perform data exports | ✓ | — |
Scoped roles
Integration Admin, Read-Only, Backup Config Admin, and Backup Config Viewer apply only to what you assign them. Integration Admin and Read-Only are scoped to assigned integrations. Backup Config Admin and Backup Config Viewer are scoped to assigned backup configurations, and are available for Jira and GitHub. Every permission in this table applies within the role's assigned scope.
| Action / permission | Integration Admin assigned integrations |
Read-Only assigned integrations |
Backup Config Admin assigned backup configurations |
Backup Config Viewer assigned backup configurations |
|---|---|---|---|---|
| Manage settings | ||||
| Configure integration settings | ✓ | — | — | — |
| Configure backup configuration settings | ✓ | — | — | — |
| View and monitor | ||||
| View backup data | ✓ | ✓ | ✓ | ✓ |
| View backup status | ✓ | ✓ | ✓ | ✓ |
| View backup and restore history | ✓ | ✓ | — | — |
| View audit log | ✓ | ✓ | — | — |
| Export audit log | ✓ | ✓ | — | — |
| Back up and restore | ||||
| Perform item-level restore | ✓ | — | ✓ | — |
| Perform advanced restore | ✓ | — | — | — |
| Perform manual backup | ✓ | — | — | — |
Scoped roles can't add or remove users, assign roles, configure organization settings, link or unlink integrations, transfer ownership, or perform data exports.
Role descriptions
Each role in Rewind supports a different responsibility within your team. Follow the principle of least privilege — grant the lowest role that still lets the person do their job. Where someone needs one set of projects rather than a whole integration, prefer Backup Config Admin or Backup Config Viewer.
-
Organization Owner
Has full access to everything in your organization, and is the only role that can transfer ownership or perform data exports. An organization has one Organization Owner. -
Organization Admin
Manages Rewind day to day — everything an Organization Owner can do except transferring ownership and performing data exports. Suits trusted team members who help run Rewind. -
Integration Admin
Manages the integrations they're assigned to. If your organization backs up two Jira sites, they see the ones they've been assigned, not both. Suits team members who own the backups for specific platforms. -
Read-Only
Views the backups for their assigned integrations, including comparing versions and checking backup and restore history for successes and failures. They can't change or restore anything. Suits auditors or team members who need visibility without control. -
Backup Config Admin
Views and restores the backed-up data within the backup configurations they're assigned to, for Jira and GitHub. They can't change the configuration itself. Suits delegating responsibility for one group of projects or repositories to the team that owns it. -
Backup Config Viewer
Views the backed-up data within the backup configurations they're assigned to, for Jira and GitHub, without being able to change or restore anything. Suits auditors or stakeholders who need visibility into a specific set of projects or repositories.
Scoping access to a backup configuration
The Backup Config Admin and Backup Config Viewer roles are part of Rewind Access Fabric, which lets you scope access to a single backup configuration rather than a whole integration. These roles are available for Jira and GitHub, on all plans, wherever backup configurations are enabled. For setup steps and guidance on mapping your Atlassian roles to Rewind roles, see Scope user access with Rewind Access Fabric.
FAQ
Can users have multiple roles?
No — each user has exactly one role. What varies is its scope. Integration Admin and Read-Only apply to the integrations you assign; Backup Config Admin and Backup Config Viewer apply to the backup configurations you assign. You can't give one person different roles on different integrations or configurations.
Can I restrict a user's access to certain integrations?
Yes. Integration Admins and Read-Only users have their permissions scoped to the integrations they're assigned to. They won't have visibility or access to integrations outside their assigned scope.
You can go a level finer. For Jira and GitHub, Backup Config Admins and Backup Config Viewers are scoped to individual backup configurations, so they see only the projects or repositories in the configurations assigned to them — not the rest of the integration. See Scope user access with Rewind Access Fabric.
What are the Backup Config Admin and Backup Config Viewer roles?
They're part of Rewind Access Fabric. They scope a user to the backed-up data in specific backup configurations instead of a whole integration — a Backup Config Admin can view and restore that data; a Backup Config Viewer can view it. Neither can change the configuration itself, see other backup configurations, or manage users, billing, or integrations. Available for Jira and GitHub on all plans. See Scope user access with Rewind Access Fabric.
Why can't I see all the backup configurations in my integration?
If you're a Backup Config Admin or Backup Config Viewer, you'll see the backup configurations you've been assigned. Ask an Organization Owner or Organization Admin to assign you more, or to tell you which you currently have.
How do I know which users have access to a particular integration?
Any user can view the user permissions under Account Settings > Team Collaboration, which indicates user roles and their integration access.
Where did the Member Permissions page go?
It's now the Team Collaboration page, in the same place under Account Settings. It's been redesigned to make it clearer who has access to what. This applies to every Rewind organization, on every integration and plan.
How do I assign roles to users?
Navigate to Account Settings > Team Collaboration to assign or adjust user roles. For steps, see How to assign or change user roles.
How do I revoke user access or change roles?
Organization Owners and Organization Admins manage roles and revoke access via Account Settings > Team Collaboration.
What if my role doesn't allow an action I need to perform?
Request elevated permissions from an Organization Owner or Organization Admin, or have them perform the required action on your behalf.
Who manages billing and subscriptions?
Billing and subscription management is available to Organization Owners and Organization Admins.
For Shopify integrations, Integration Admins can also manage billing and subscriptions in order to change store plans. This is a unique exception to the standard RBAC rules.
How does RBAC work with Single Sign-On (SSO)?
When SSO is enabled, your identity provider assigns each user's role. Organization Admin, Integration Admin, and Read-Only can be assigned this way. Rewind doesn't support Backup Config Admin or Backup Config Viewer through SSO yet, so you can't assign them in an organization that uses SSO.
SSO setup requires assistance from the Rewind Support team. To enable SSO for your organization, or for guidance on adding Rewind role attributes to your existing SSO configuration, contact help@rewind.com.
How is organization ownership transferred?
Ownership can be transferred by the Organization Owner through account settings, confirmed via email verification. For steps, see How to transfer Rewind organization ownership.
What happens to the previous owner's permissions after transferring ownership?
After transferring ownership, the previous Organization Owner is automatically assigned the Organization Admin role, so they retain administrative access.
What happens if the Organization Owner has left the company?
If ownership wasn't transferred before their departure, another authorized user should contact Rewind Support for guidance on securely transferring ownership.
To ensure continuity, set up a dedicated service account as the Organization Owner. This ensures uninterrupted access and backup management if an individual leaves your organization.
Related articles
- How to assign or change user roles
- How to add and remove members within your Rewind organization
- How to transfer Rewind organization ownership
- Scope user access with Rewind Access Fabric
Need help?
If you have questions or need assistance, contact help@rewind.com or submit a request.