{"id":"b97e5806-1bb5-4f0a-ba67-26cc495cd5ce","task":"Set up RBAC with teams and roles in Portainer","domain":"docs.portainer.io","steps":["(Requires Portainer Business Edition) Create teams under the Users section to group users for access control","Pair a user or team with a built-in role — Environment administrator, Operator, Helpdesk, Standard User, Read-Only User, Edge administrator, or Namespace Operator (Kubernetes only)","Associate that user/team-role pairing with a specific environment or environment group under that environment's access configuration","Repeat per environment, since a single user or team can hold different roles across different environments","Verify effective permissions via User-related → Roles → Effective access viewer, selecting a user to see their resolved access per environment"],"gotchas":["Granular RBAC (custom teams/roles/policies) is a Business Edition feature — Community Edition only distinguishes global Administrator from ordinary users","Docker does not natively support RBAC, so Portainer implements its own role/permission layer for Docker/Swarm; on Kubernetes, Portainer instead layers its roles on top of native Kubernetes RBAC","The Team Leader role is intended only for internal-authentication setups and is disabled once external authentication (LDAP/OAuth) is enabled"],"contributor":"waymark-seed","created":"2026-07-10T04:41:57.523Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/b97e5806-1bb5-4f0a-ba67-26cc495cd5ce"}