Manage the baseline policy applicable for each workspace within your RudderStack organization.
Available Plans
enterprise
3 minute read
This guide explains how to manage the baseline policy applicable for each workspace within your RudderStack organization.
Overview
The Baseline Workspace Policies tab lists all the workspaces available in your RudderStack organization along with details like number of groups and members within each workspace. Each workspace has one baseline policy.
This tab also lets you configure and manage the baseline policy applicable to each workspace in your RudderStack organization. All the groups, members, and Service Access Tokens in that workspace automatically inherit this baseline policy.
For example, an Admin can give every member the ability to create sources and destinations for testing purposes in the Dev workspace.
Use cases
Baseline workspace policies are useful for configuring permissions that should apply by default across an entire workspace. Some common use cases include:
Increasing access in Dev workspaces to streamline testing and troubleshooting
Ensuring restricted access in Prod workspaces to protect production pipelines and PII
Enabling self-serve configuration of low-impact resources (like Alerts)
Examples
Give every member the ability to create sources and destinations for testing purposes in the Dev workspace.
Give access to Live Events PII permissions in Dev workspace so that anyone in the workspace can test and troubleshoot, but restrict Live Events access in Prod to ensure InfoSec compliance.
Grant permissions for Alert Overrides so that different team members can configure resource-specific notifications that are relevant to their role/team.
Instead of editing each individual member’s policy or even creating a group for such use cases, they can simply configure a baseline policy to grant the required permissions within that workspace.
Plan-wise limits
Not all RudderStack plans allow customizing the baseline workspace policy. See the Plan-wise Features guide for more details on baseline workspace policy limits across different plans.
Default behavior
Unless otherwise configured by an Admin, the baseline workspace policy is set to:
Use the policy editor to configure the baseline workspace policy for that workspace.
All the groups, members, and Service Access Tokens in that workspace will automatically inherit the baseline workspace policy.
Configure permissions for different resources and PII.
Click Save to save the configuration and enforce the baseline workspace policy.
Important considerations
In RudderStack’s Access Management system, the permissions are additive, meaning users inherit all permissions granted to them via the baseline workspace policy, Group Workspace Policy, and Member Workspace Policy. Permissions are accumulated, never overridden or subtracted.
When configuring a baseline workspace policy, RudderStack recommends adopting a minimum necessary access principle. This ensures that onboarding users with restricted access needs (like contractors or external collaborators) can be done without major rework later on.
Adjusting an established baseline workspace policy later can cause broad ripple effects across your organization. It may affect the permissions of existing users and require substantial effort and rework to restore the intended security and access levels.
Questions? We're here to help.
Join the RudderStack Slack community or email us for support
This site uses cookies to improve your experience while you navigate through the website. Out of
these
cookies, the cookies that are categorized as necessary are stored on your browser as they are as
essential
for the working of basic functionalities of the website. We also use third-party cookies that
help
us
analyze and understand how you use this website. These cookies will be stored in your browser
only
with
your
consent. You also have the option to opt-out of these cookies. But opting out of some of these
cookies
may
have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This
category only includes cookies that ensures basic functionalities and security
features of the website. These cookies do not store any personal information.
This site uses cookies to improve your experience. If you want to
learn more about cookies and why we use them, visit our cookie
policy. We'll assume you're ok with this, but you can opt-out if you wish Cookie Settings.