Teams & permissions

Access reflects the action’s real blast radius.

Data Convoy separates viewing, safe copying, production deletion, paid retrieval, team administration, and bucket redirection into explicit permissions.

Default role model

The four fixed roles are backed by a permission matrix that site administrators can edit.

Viewer

Read-only access to team jobs and state.

User

Dry runs, scheduled work, and archive/backup copies that leave production intact.

Manager

Destructive jobs plus member and worker management; no bucket repointing.

Owner

Full team control, including buckets, roles, ownership transfer, and deletion.

Server enforcement, live revocation

APIs compute permissions from the requested operation and enforce them server-side. User-to-role mappings are not TTL-cached, so removing a role immediately changes claim and request authorization.

Your buckets. Your workers. Your control.

Make the next archive reversible.