Managing Access to Projects
Business Objective: Rapid Onboarding with Accountability & Scalable Team Management
This guide teaches you how to achieve rapid user onboarding (minutes instead of days) and zero-touch team scaling using Infrastream Agent and Infrastream's group-based access model. By the end of this guide, you'll be able to:
✅ Onboard new team members in minutes using Infrastream Agent to create access requests
✅ Manage entire teams via groups for instant onboarding and offboarding
✅ Maintain complete audit trails for SOC2, ISO 27001, and HIPAA compliance
✅ Enforce Zero Trust principles with precisely scoped project permissions
For the exact Google Cloud permissions each tier confers, see Access Tiers.
This implements business use cases:
- Use Case 1: Rapid User Onboarding with Accountability
- Use Case 2: Scalable Team Management via Groups
How It Works: The Infrastream Agent Workflow
Access management follows a simple, governed workflow:
- Manager initiates request → Uses Infrastream Agent in the portal: "Add jane-smith to the payments-contributors group"
- Infrastream Agent creates PR → Automatically generates a Pull Request modifying the group manifest
- Approval workflow → PR routes to organization administrators for review
- Instant provisioning → Once merged, user gets access within 2-5 minutes
- Permanent audit trail → Git commit records who requested, who approved, when granted
Why Infrastream Agent? By using Infrastream Agent instead of manual file editing, you get:
- Simplified workflow for non-technical managers
- Consistent manifest formatting
- Built-in validation before submission
- Integration with approval workflows
Understanding Project Permissions
Infrastream projects support three permission levels, each with specific capabilities:
Permission Levels
| Role | Capabilities |
|---|---|
| Administrators | Full control: manage resources, modify permissions, delete project |
| Contributors | Create and modify resources, deploy applications, cannot change permissions |
| Viewers | Read-only access to view resources and configurations |
You grant access via Infrastream Name Abstractions. These reference the metadata.name of the corresponding identity manifests:
- Users: Referenced by their
OrganizationUsername (e.g.,jane-smith). - Groups: Referenced by their
OrganizationUserGroupname (e.g.,payments-contributors).
[!IMPORTANT] Production Security Rule: Individual members (
members:) are strictly disallowed for production and financial projects. All access must be granted via groups (groups:) to ensure compliance (SOC2/PCI) and scalable governance.
Use Case 1: Managing Team Membership via Groups
Business Goal: Enable rapid onboarding with full accountability, eliminating IT ticket delays.
Scenario
A new developer, Jane Smith (jane-smith), joins your team and needs contributor access to the astrapay-prod project. Instead of adding her directly to the project (which is restricted in production), you'll add her name abstraction to the payments-contributors group.
The Infrastream Agent Approach
Step 1: Initiate request via Infrastream Agent
In the Infrastream portal, use Infrastream Agent:
Infrastream Agent: How can I help you today?
You: Add jane-smith to the payments-contributors group
Infrastream Agent:I have successfully created a Pull Request to add `jane-smith` to the `payments-contributors` group.
Since the the user `jane-smith` did not exist, I created manifests for both:
1. **User**: `jane-smith` (Jane Smith)
2. **Group**: `payments-contributors` (with `jane-smith` as a member)
You can review the changes here: [PR #10](https://github.com/astrapay/astrapay-infrastream-organization-manifests/pull/10)
Step 2: Approval and merge
Once an admin approves and merges, Jane gets access within 2-5 minutes.
Alternative: Manual Manifest Editing
If you prefer to edit manifests directly (for advanced users):
Step 1: Locate the Project Manifest
Navigate to your project manifest file:
organizational-unit/payments/
└── environment/production/
└── project/astrapay-prod/
└── astrapay-prod.yaml
Step 2: Edit the Project Manifest
Open the project manifest and locate the permissions section. Add Jane's email to the contributors.members list:
apiVersion: lowops.manifests.v1
kind: Project
metadata:
name: astrapay-prod
environment: production
organizational-unit: payments
organization: acme-corp
spec:
description: AstraPay Payment Processing Platform
permissions:
administrators:
groups:
- platform-team # Name abstraction
members: [] # Production Policy: Keep empty
contributors:
groups:
- payments-contributors
members: []
viewers:
groups:
- qa-team
members: []
Step 3: Submit and Merge
- Create a Pull Request with your changes
- Request approval from a project administrator
- Merge the PR once approved
Result: Within minutes of merging, Jane will have contributor access to the astrapay-prod project. She can deploy applications, create databases, and manage secrets—but cannot modify project permissions.
Audit Trail
The Git history provides a complete audit trail:
- Who requested the access (PR author)
- When it was requested (PR timestamp)
- Who approved it (PR reviewer)
- When it was granted (merge timestamp)
Use Case 2: Adding a Group to a Project
Scenario
Your organization has a GitHub team called backend-developers with 25 members. You want to grant this entire team contributor access to the api-gateway project rather than adding 25 individual users.