UI Guide

Admin & Permissions

/admin is visible only to users holding the Admin role. This is where you manage who can use Maestro-π and what they're allowed to do.

Administration — users and roles
  • User table — columns User, Roles, Status, Added and Actions: every provisioned user, their assigned roles (click a role badge to toggle it on/off for that user), whether they are Active or Disabled, and when they were added.
  • Add User — provisions a new Maestro-π user. You pick an existing platform login (the dropdown searches the connected identity directory's users) — Maestro-π never stores a password; sign-in is always delegated to the host platform's identity.
  • Disable / Remove — Disable blocks sign-in without deleting the record; Remove deletes it outright (does not touch the underlying platform account).
  • Roles overview (bottom of page) — a quick-glance card per role; click one to manage it.

Roles & Permissions#

Click Roles & Permissions at the top of the page for the full list — each card in the Roles overview also has its own Manage → link:

Roles & Permissions list

Five roles ship built-in (Admin, Op, Editor, Viewer, Public) and are read-only — you can view what they grant but not edit them. Click Create Role to define a custom role with its own permission set.

Role permission matrix#

Clicking any role (built-in or custom) opens its permission matrix — a grid of resources (DAGs, DAG Runs, Tasks, Connections, Variables, Pools, System) against actions (view, edit, trigger, delete, clear, mark, admin):

Role permission matrix — Viewer

For built-in roles the checkboxes are locked (read-only, as noted on the page). For a custom role, tick the boxes you want and click Save permissions. Remember: these are role-level defaults — the per-DAG Access tab can grant narrower, DAG-specific exceptions on top.