Skip to main content

Role Management

With Appcircle's Advanced Role Management structure, you can assign specific roles to organization members for each module, allowing you to manage and restrict their permissions effectively. Appcircle provides various role types for each module, with a brief description of each role provided in the table below. For more detailed information on role management for each module, please refer to the respective module titles.

  • Owner: The user is authorized for unlimited access to all modules.
  • Manager: The user becomes the administrator of the relevant module with no restrictions.
  • Operator: The user manages the operations of the relevant module, with certain restrictions in place.
  • Ext. Operator: The user has very limited authorization in the relevant module, typically intended for third-party employees from outside the company.
  • Viewer: The user only has view authorization in the relevant module and cannot take any action.
Role Types

Some role types are not used in certain modules because they are redundant or unnecessary, as they serve the same function as another role. Therefore, roles may vary for each module.

Multiple Role Assignment for Users

When assigning roles on Appcircle, you can assign more than one role for a user at the same time. For example, a user can be both Manager and Operator in the Build module.

For this reason, Appcircle behavior will change when multiple roles are assigned. For example, you have assigned Ext Operator and Viewer role in Publish to Stores Module for a user. This means that the Ext Operator role now has the privileges of the Viewer role. So while Ext Operator cannot see Activity logs, it now has access to those logs because it also has the viewer role.

Build Permissions​

The following table details the roles and restrictions for the Build module. Please refer to the related module information and caution notes.

Build Sub-modulesScopesOwnerManagerOperatorViewer
Build ProfileAdd/Delete/Update Build Profiles✅✅⛔⛔
Build ProfileList Build Profiles✅✅✅✅
Build ProfileBuild List✅✅✅✅
RepositoryConnect/Disconnect Repository✅✅⛔⛔
WebhookView Webhook URL, Webhook Key✅✅✅✅
WebhookGenerate Webhook Key✅✅⛔⛔
ConfigurationAdd/Delete/Update Build Configuration✅✅⛔⛔
ConfigurationView Build Configuration✅✅✅✅
WorkflowAdd/Delete/Update Workflows✅✅⛔⛔
WorkflowView Workflows✅✅✅✅
TriggersAdd/Delete/Update Triggers✅✅⛔⛔
TriggersView Triggers✅✅✅✅
Build ActionsStart Build✅✅✅⛔
Build ActionsDelete Commit Artifacts✅✅⛔⛔
Build ActionsDownload Artifacts✅✅✅✅
Build ActionsDistribution Binary✅✅✅⛔
Build ActionsView Build Cache Size Usage✅✅✅✅
Build ActionsClear Build Caches✅✅⛔⛔
Test ResultsList Test Results✅✅✅✅
ConnectionAdd/Delete/Update Connections (User Based)✅✅✅✅
ConnectionList Connection (User Based)✅✅✅✅
RunnerAdd/Delete/Update Runner(Root Only)✅⛔⛔⛔
RunnerList Runner(Root Only)✅✅✅✅
Runner Access TokenCreate/Delete Runner Access Token✅⛔⛔⛔
Runner Access TokenList Runner Access Token✅⛔⛔⛔
ReportList Build Reports✅✅✅✅
Build CacheView Build Cache Usage✅✅✅✅
Build CacheDelete Build Cache✅✅⛔⛔
Build HistoryView Build History✅✅✅✅
Build Activity LogView Build Activity Log✅✅✅✅
AI Build AnalysisView Build Analysis✅✅✅✅
AI Build AnalysisStart Build Analysis✅✅✅⛔
Distribution Binary and Runner Details
  • Manager or Operator Build Profile permission can distribute binary if user has Manager or Operator distribution permission.
  • Manager or Operator Build Profile permission can publish if user has Manager or Operator Publish Android/iOS permission.
  • Manager, Operator and Viewer Build Profile permissions can view self-hosted runners but cannot modify the configuration.
AI Build Analysis
  • View Build Analysis (build#get_build_analysis) and Start Build Analysis (build#start_build_analysis) follow the same role mapping as viewing builds and starting builds.
  • Starting a build analysis consumes AI credits (license#use_ai_credit) from the organization's shared monthly AI credit pool. All AI features draw from this single pool.
  • A user without the required role receives a 403 Forbidden response. When the organization has no AI credits left, the request is rejected with a 402 Payment Required response.
  • AI features can only be used after the organization has accepted the AI consent. See Organization Management Permissions.

Environment Variables Permissions​

The following table details the roles and restrictions for the Environment Variables. Please refer to the related module information and caution notes.

Environment VariableScopesOwnerManagerViewer
Environment VariableAdd/Delete/Update Environment Variable Groups✅✅⛔
Environment VariableAdd/Delete/Update Environment Variable✅✅⛔
Environment VariableList Environment Variable✅✅✅
Environment VariableList Environment Variable Groups✅✅✅
info

Manager, Operator and Viewer Environment Variable permissions can use variable groups in Build profile configuration.

CodePush Permissions​

The following table details the roles and restrictions for the CodePush. Please refer to the related module information and caution notes.

CodePushScopesOwnerManagerOperatorViewer
CodePush ProfileAdd/Delete/Update✅✅⛔⛔
Deployment ChannelAdd/Delete/Update✅✅⛔⛔
ReleaseRelease Version/Rollback✅✅✅⛔
Deployment KeysList/Copy✅✅✅⛔
Release VersionList✅✅✅✅
Release VersionPromote/Settings Update/Download✅✅✅⛔

Signing and Identity Permissions​

The following table details the roles and restrictions for the Signing and Identity module. Please refer to the related module information and caution notes.

Signing Identity Sub-modulesScopesOwnerManagerViewer
Apple CertificateAdd/Delete/Download Apple Certificates and CSRs✅✅⛔
Apple CertificateConvert a CSR to .p12✅✅⛔
Apple CertificateList Apple Certificates and CSRs✅✅✅
Apple IdentifiersAdd/Delete/Update Apple Identifiers✅✅⛔
Apple IdentifiersList Apple Identifiers✅✅✅
Apple DeviceAdd Device Manuel✅✅⛔
Apple DeviceInvite User via Email✅✅⛔
Apple DeviceDelete Apple Device✅✅⛔
Apple DeviceSync from Apple Developer✅✅⛔
Apple DeviceRegister Devices to Apple Developer✅✅⛔
Apple DeviceAdding New Device to Provision✅✅⛔
Apple DeviceList Apple Device✅✅✅
Apple ProfileAdd/Delete/Update Apple Profiles✅✅⛔
Apple ProfileList Apple Profiles✅✅✅
KeystoreAdd/Delete/Update Keystores✅✅⛔
KeystoreList Keystores✅✅✅
ReportList Signing Reports✅✅✅
Activity LogsList Activity Log Details✅✅✅
Signing and Identities

Manager and Viewer Signing Identity permissions can use signing identities in Build profile configuration.

Signing Identity Permission
    • Manager Signing Identity permission can delete Apple Certificates and Apple Profiles if user has Manager Build permission.

Testing Distribution Permissions​

The following table details the roles and restrictions for the Testing Distribution module. Please refer to the related module information and caution notes.

Testing DistributionScopesOwnerManagerOperatorExt. OperatorViewer
Distribution ProfileAdd/Delete/Update Distribution Profile✅✅⛔⛔⛔
Distribution ProfileSetting Update Distribution Profile✅✅⛔⛔⛔
Distribution ProfileList Distribution Profiles✅✅✅✅✅
App VersionAdd/Delete/Update App Version✅✅✅✅⛔
App Version ActionsSend to Testers✅✅✅✅⛔
App Version ActionsSend to Enterprise App Store✅✅✅⛔⛔
App Version ActionsSend to Publish✅✅✅⛔⛔
App Version ActionsDownload Binary✅✅✅✅⛔
SettingsSelect Authentication Type✅⛔⛔⛔⛔
SettingsView Authentication Settings✅✅✅⛔✅
Session ManagementSingle Active Session✅⛔⛔⛔⛔
Auto Re-sign ConfigurationList/Update Auto Re-sign Configuration✅✅⛔⛔⛔
ReportList Reports App Version✅✅✅⛔✅
ReportList Reports App Sharing✅✅✅⛔✅
Activity LogsList Activity Log Details✅✅✅⛔✅
Authentication Settings

If the selected Authentication type is Static login, Manager role can change Username and Password. However, it cannot change the content for other Authentication types such as LDAP or SSO.

Share with Tester

Users can share the binary with registered Tester Groups only if they have Viewer or higher Testing Group permission. However, users can still share the binary with individual testers by adding them manually.

Sending Binary
  • Manager or Operator Distribution Profile permission can send to Enterprise App Store if user has Manager or Operator Enterprise App Store permission.
  • Manager or Operator Distribution Profile permission can send to Publish if user has Manager or Operator Publish Android and Manager or Operator iOS permission.
  • Manager or Operator Distribution Profile permission can resign binary if user has Manager or Viewer Signing Identity Management permission.
Resign Binary

User can resign the binary if this user has Manager or Viewer Signing Identity permission

Testing Group Permissions​

The following table details the roles and restrictions for the Testing Groups. Please refer to the related module information and caution notes.

Testing GroupsScopesOwnerManagerViewer
Testing GroupsAdd/Delete/Update Testing Group✅✅⛔
Testing GroupsAdd/Delete/Update Testing Group Testers✅✅⛔
Testing GroupsList Testing Groups✅✅✅
Testing GroupsList Testing Group Testers✅✅✅
Testing GroupsUpdate LDAP Group Members Synchronization✅✅⛔
Testing GroupsSync Testing Group From LDAP✅✅⛔
Testing GroupsList LDAP Groups and Members✅✅✅

Publish to Stores Module iOS Permissions​

The following table details the roles and restrictions for the Publish module for iOS. Please refer to the related module information and caution notes.

PublishScopesOwnerManagerOperatorExt. OperatorViewer
Publish ProfilesAdd/Delete/Update Publish Profile✅✅⛔⛔⛔
Publish ProfilesList Publish Profiles✅✅✅✅✅
App VersionAdd/Delete App Version✅✅✅✅⛔
App VersionList App Versions✅✅✅✅✅
Profile SettingsView/Update Profile Settings✅✅⛔⛔⛔
Publish FlowsAdd/Delete/Update Publish Flow Step✅✅⛔⛔⛔
Publish FlowsDownload Publish Flow✅✅⛔⛔⛔
Publish FlowsUpload Publish Flow✅✅⛔⛔⛔
Publish FlowsView Publish Flow✅✅⛔⛔⛔
PublishStart/Restart/Stop Flow✅✅✅⛔⛔
PublishStart Single Step✅✅✅⛔⛔
PublishUpdate Publish Details✅✅✅⛔⛔
PublishView Publish Details✅✅✅✅✅
App Store Connect InfoList/Update App Store Connect Information✅✅⛔⛔⛔
TestFlight Beta InfoList/Update TestFlight Beta Information✅✅⛔⛔⛔
Auto Re-sign ConfigurationList/Update Auto Re-sign Configuration✅✅⛔⛔⛔
Check Release StatusGet Relese Status✅✅✅✅✅
Metadata DetailsUpdate Metadata Details✅✅✅✅⛔
Submit for Beta TestingView Submit for Beta Testing✅✅✅✅✅
Submit for Beta TestingBeta Submission✅✅⛔⛔⛔
App Release InformationView App Release Information✅✅✅✅✅
App Release InformationUpdate App Release Information✅✅⛔⛔⛔
Mark as RCMarking RC a version✅✅✅⛔⛔
Binary InformationList Binary Information✅✅✅✅✅
Binary ComparisonList Binary Comparison✅✅✅✅✅
Resing BinaryResigning Binary✅✅✅⛔⛔
Release NoteUpdate Release Note✅✅✅✅⛔
HistoryView/Download History Logs✅✅✅✅✅
HistoryList History✅✅✅✅✅
Download BinaryDownload Binary✅✅✅⛔✅
Cancel SubmissionCancel Submission✅✅✅⛔⛔
Reject BinaryReject Binary✅✅✅⛔⛔
Activity LogsList Activity Log Details✅✅✅⛔✅
Resign Binary

User can resign the binary if this user has Manager or Viewer Signing Identity permission

Publish to Stores Module Android Permissions​

The following table details the roles and restrictions for the Publish module for Android. Please refer to the related modules information and caution notes.

PublishScopesOwnerManagerOperatorExt. OperatorViewer
Publish ProfilesAdd/Delete/Update Publish Profile✅✅⛔⛔⛔
Publish ProfilesList Publish Profiles✅✅✅✅✅
App VersionAdd/Delete App Version✅✅✅✅⛔
App VersionList App Versions✅✅✅✅✅
Profile SettingsView/Update Profile Settings✅✅⛔⛔⛔
Publish FlowsAdd/Delete/Update Publish Flow Step✅✅⛔⛔⛔
Publish FlowsDownload Publish Flow✅✅⛔⛔⛔
Publish FlowsUpload Publish Flow✅✅⛔⛔⛔
Publish FlowsView Publish Flow✅✅⛔⛔⛔
PublishStart/Restart/Stop Flow✅✅✅⛔⛔
PublishStart Single Step✅✅✅⛔⛔
PublishUpdate Publish Details✅✅✅⛔⛔
PublishView Publish Details✅✅✅✅✅
Google Play Console InformationList/Update Google Play Console Information✅✅⛔⛔⛔
Auto Re-sign ConfigurationList/Update Auto Re-sign Configuration✅✅⛔⛔⛔
MetadataUpdate Metadata Details✅✅✅✅⛔
MetadataView Metadata Details✅✅✅✅✅
App Rollout InformationView App Rollout Information✅✅✅✅✅
App Rollout InformationUpdate App Rollout Information✅✅⛔⛔⛔
App Rollout InformationUpdate Rollout Status✅✅⛔⛔⛔
Mark as RCMarking RC a version✅✅✅⛔⛔
Binary InformationList Binary Information✅✅✅✅✅
Binary ComparisonList Binary Comparison✅✅✅✅✅
Resing BinaryResigning Binary✅✅✅⛔⛔
Release NoteUpdate Release Note✅✅✅✅⛔
HistoryView/Download History Logs✅✅✅✅✅
HistoryList History✅✅✅✅✅
Download BinaryDownload Binary✅✅✅⛔✅
Reject BinaryReject Binary✅✅✅⛔⛔
Activity LogsList Activity Log Details✅✅✅⛔✅

Publish Environment Variables​

The following table details the roles and restrictions for the Publish Variables module for Android. Please refer to the related modules information and caution notes.

PublishScopesOwnerManagerViewer
Environment VariableAdd/Delete/Update Environment Variable Groups✅✅⛔
Environment VariableAdd/Delete/Update Environment Variable✅✅⛔
Environment VariableList Environment Variable✅✅✅
Environment VariableList Environment Variable Groups✅✅✅
info

Google Play and Huawei AppGallery permissions are managed through a single rule. When this rule is used, it will apply to both platforms.

Enterprise App Store Permissions​

Manage and Upload Apps to Enterprise App Store.

Ent. App Sub ModulesScopesOwnerManagerOperatorExt. OperatorViewer
Store ProfileAdd/Delete/Update Profiles✅✅✅⛔⛔
Store ProfileList Profiles✅✅✅✅✅
App VersionAdd/Delete/Update App Versions✅✅✅✅⛔
App VersionDownload App Versions✅✅✅✅⛔
App VersionList App Versions✅✅✅✅✅
App Version ActionsPublish App Version Live/Beta Channels✅✅✅⛔⛔
App Version ActionsNotify Users✅✅✅⛔⛔
App Version ActionsCreate/Delete In-app Update✅✅✅⛔⛔
App Version ActionsGet In-app Update✅✅✅✅✅
SettingsUpdate Store Domain✅⛔⛔⛔⛔
SettingsUpdate Store Customization✅⛔⛔⛔⛔
SettingsSelect Authentication Type✅⛔⛔⛔⛔
SettingsView Authentication Settings✅✅✅⛔✅
SettingsView Customization Settings✅✅✅⛔✅
SettingsView Store Domain✅✅✅⛔✅
Re-sign BinaryRun Manual Re-sign✅✅✅⛔⛔
Re-sign BinaryView Auto Re-sign Settings✅✅⛔⛔⛔
Re-sign BinaryEdit Auto Re-sign Settings✅✅⛔⛔⛔
Session ManagementSingle Active Session✅⛔⛔⛔⛔
ReportList Reports✅✅✅⛔✅
Activity LogsList Activity Log Details✅✅✅⛔✅
Authentication Settings

If the selected Authentication type is Static login, Manager role can change Username and Password. However, it cannot change the content for other Authentication types.

Organization Management Permissions​

The user can create an organization or sub-organization within license limits, add and remove members, and manage their permissions.

Also, the user can view self-hosted runners and change configuration.

Organization Management Sub-modulesScopesOwnerManagerViewer
Organization and Team ManagementCreate/Delete/Update Organization✅✅⛔
Organization and Team ManagementCreate/Delete/Update Sub-Organization✅✅⛔
Organization and Team ManagementAdd/Delete/Update User✅✅⛔
Organization and Team ManagementAssign Role for User✅✅⛔
Organization and Team ManagementList User✅✅✅
Testing Portal and Enterprise Portal AuthenticationsAdd/Delete/Update LDAP/SSO Integrations✅✅⛔
Testing Portal and Enterprise Portal AuthenticationsView LDAP/SSO Integrations✅✅✅
Appcircle LoginCreate/Delete/Update SSO✅✅⛔
Appcircle LoginList SSO✅✅✅
Appcircle LoginAdd/Delete/Update LDAP✅✅⛔
Appcircle LoginList LDAP✅✅✅
Runner Access TokenList Runner Access Token✅⛔⛔
Runner Access TokenCreate/Delete Runner Access Token✅⛔⛔
ReportView Organization Activity Log✅✅✅
ReportView Authentication Activity Log✅✅✅
ArtifactsView Retention Period✅✅✅
ArtifactsUpdate Retention Period✅✅⛔
ArtifactsView Artifacts Report✅✅✅
Domain VerificationView Domain List✅✅✅
Domain VerificationView Domain Verification Details✅✅⛔
Domain VerificationAdd New Domain Verification✅✅⛔
Domain VerificationVerify a Domain✅✅⛔
Domain VerificationRemove Domain Verification✅✅⛔
Export UsersExport User List✅✅⛔
API KeysView API Keys List✅✅✅
API KeysManage/Delete API Keys✅✅⛔
AI FeaturesAccept AI Consent✅✅⛔
AI Consent

Accepting the AI consent (organization#accept_ai_consent) enables AI features for the organization. Only users with the Owner or Manager Organization Management role can accept it; other users receive a 403 Forbidden response.

Organization Management

Whatever role a user is assigned in the root organization, they will have the same role in the sub-organizations. For example, someone who is a Manager in the root organization is automatically assigned as a Manager in the sub-organizations.

If you want to assign a role in a sub-organization, please do so within the respective sub-organization.

Appcircle Login and LDAP/SSO Integrations

LDAP/SSO integrations under Integration are only for setting authentication for logins to the Testing Distribution Testing Portal and Enterprise App Store.

Please use Appcircle Login for LDAP and SSO integration when logging into Appcircle.

Organization Management Role Assignment

The Manager role cannot assign itself and another user as Owner when assigning roles.

Billing Management Permissions​

Manage the subscription, payment details, and invoices.

The following table details the roles and restrictions for the Billing details. Please refer to the related module information and caution notes.

Billing Sub-modulesScopesOwnerManager
SubscriptionList Subscription Details✅✅

Integrations and Connection Managements​

Connect or disconnect from third-party service providers such as notification tools or store connections.

Notification Tools​

Store Connections​

Integrations and ConnectionsScopesOwnerManagerViewer
Store CredentialsAdd/Delete/Update Credentials✅✅⛔
Store CredentialsShare Credentials✅✅⛔
Store CredentialsView Credentials✅✅✅
NotificationsUpdate/Delete Notifications✅✅⛔
NotificationsView Notifications✅✅✅
Activity LogsList Activity Log Details✅✅✅