Global roles versus CSTAR roles
This document separates two different authorization layers that are easy to confuse.
Short version
| Layer | Scope | Source | Examples |
|---|---|---|---|
global n8n role | platform-wide | OIDC role claim, CSTAR managed project-role fallback, or access-request approval | global:owner, global:admin, global:member |
| CSTAR tenant role | tenant-scoped | CSTAR | project:editor, project:viewer, ui:actor |
Global roles
Global roles are n8n user roles.
They determine baseline platform privileges such as:
- admin-only UI access
- admin-only custom API access
- access-request review
- other global permission checks in the UI
Current global roles:
global:ownerglobal:adminglobal:member
These roles are not tied to a specific tenant.
CSTAR tenant roles
CSTAR tenant roles are per-tenant shared-service roles and groups.
They are used for:
- determining whether the user should be in a tenant's
n8nteam project - determining whether the user should be
project:editororproject:viewer - role-based and group-based WIL actor matching
- tenant-scoped UI behavior
These roles are tenant-specific, not platform-wide.
How they interact
The two layers are related but different.
- A user needs a usable global role to function normally in the platform.
- A user can receive
global:memberduring login if they have any CSTAR managed project role in any tenant and no upstream global role was provided. - CSTAR tenant data then determines which tenant projects that user can access.
- A user can be
global:memberand still have zero tenant projects. - A user can belong to multiple CSTAR tenants and have different CSTAR roles in each one.
Example
User alex@gov.bc.ca:
- global role:
global:member - CSTAR tenant A roles:
project:editor,ui:actor - CSTAR tenant B roles:
project:viewer
Result:
- Alex can sign in and use the platform as a normal member.
- Alex becomes
project:editorin tenant A'sn8nteam project. - Alex becomes
project:viewerin tenant B'sn8nteam project. - Alex is not a platform admin.
Common mistake to avoid
Do not use CSTAR tenant roles as if they were global platform roles.
Examples:
project:editordoes not make a userglobal:adminglobal:memberdoes not guarantee access to any tenant team projectui:actorcan matter for WIL matching without changingn8nproject membership
Related docs
docs/platform/authentication-and-authorization.mddocs/platform/cstar-role-mapping-rules.mddocs/external-ui/tenant-roles-in-session.mddocs/external-ui/tenant-project-sync.md