# Role-based access control (RBAC)
Workato plans to launch a new role-based access control system that separates workspace permissions into environment roles and project roles. This model provides granular control over access at both the environment and project levels.
Explore the following guides to learn how to configure access, migrate legacy roles, and integrate with Workato's Developer and Embedded APIs.
EARLY ACCESS FEATURE
This documentation describes a feature in limited preview. The access control model is under active development and may change. To join the early access program, contact your Customer Success Manager and ask them to add you to the early adopters list.
# Manage workspace collaborators with role-based access control
This guide explains how environment roles and project roles define access across your workspace. It covers key concepts, role behavior, and how to use collaborator groups in the new model.
Refer to Manage workspace collaborators with role-based access control to configure and assign roles in your workspace.
# Migrate to the new access control model
Use the built-in migration wizards to convert legacy system and custom roles to the new model. This guide walks through the steps to upgrade roles and optimize your access setup.
Refer to Migrate to the new access control model for more information.
# Developer API – Role-based access control
You can use Workato's Developer API to programmatically manage collaborators, roles, and permissions. These guides support teams that automate access management or integrate it with external systems:
- Legacy roles: Manage roles that use the old permissions model.
- Role migration: Migrate roles from the old permissions model to the new model.
- Environment roles: Manage roles that control access at the environment level.
- Project roles: Manage roles that control access at the project level.
- Collaborator groups: Use groups to standardize and manage permissions for multiple collaborators at a time.
- Project grants: Manage project roles assignments.
- Workspace collaborators: Manage collaborators and their privileges.
# Embedded API – Role-based access control
You can use Workato's Embedded API to programmatically manage collaborators, roles, and permissions in customer workspaces. These guides support teams that automate access management or integrate it with external systems:
- Legacy roles: Manage roles that use the old permissions model.
- Role migration: Migrate roles from the old permissions model to the new model.
- Environment roles: Manage roles that control access at the environment level.
- Project roles: Manage roles that control access at the project level.
- Collaborator groups: Use groups to standardize and manage permissions for multiple collaborators at a time.
- Project grants: Manage project roles assignments.
- Customer workspace collaborators: Invite collaborators to a customer workspace.
- Manage customers: Manage customers and their workspace collaborators.
# Frequently asked questions
This FAQ answers common questions about project roles, collaborator groups, deployment permissions, SAML/SCIM integration, and migration behavior in the new role-based access control model.
Refer to Role-based access control FAQs for more information.
Last updated: 10/14/2025, 4:38:57 PM