Roles and permissions

  • Tier: Free, Premium, Ultimate
  • Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated

Roles define a user’s permissions in a group or project.

Users with administrator access have all permissions and can perform any action.

Roles

When you add a user to a group or project, you assign them a role. The role determines their permissions. Assign either a default role or a custom role.

A user can have different roles for each group and project. Users always retain the permissions for their highest role. For example, if a user has:

  • The Maintainer role for a parent group
  • The Developer role for a project in that group

The user inherits the permissions for their Maintainer role in the project.

To view assigned roles, go to the Members page for a group or project.

Default roles

Roles are ordered from the fewest permissions to the most. The Guest, Reporter, Developer, Maintainer, and Owner roles are cumulative, so each role includes most of the permissions of the roles before it. The Planner and Security Manager roles are specialized for planning and security work, so they do not include all the permissions of the other roles. To confirm whether a role has a specific permission, check the relevant table.

The following default roles are available:

RoleDescription
Minimal AccessView limited group information without access to projects. For more information, see users with Minimal Access.
GuestView and comment on issues and epics. Cannot push code or access repository. This role applies to private and internal projects only.
PlannerCreate and manage issues, epics, milestones, and iterations. Focused on project planning and tracking with the ability to view and collaborate on code changes.
ReporterView code, create issues, and generate reports. Cannot push code or manage protected branches.
Security ManagerView and manage security vulnerabilities, compliance configurations, and audit events. Focused on security operations without code push access.
DeveloperPush code to non-protected branches, create merge requests, and run CI/CD pipelines. Cannot manage project settings.
MaintainerManage branches, merge requests, CI/CD settings, and project members. Cannot delete the project.
OwnerFull control over the project or group, including deletion and visibility settings.

By default, all users can create top-level groups and change their usernames. Users with administrator access can change this behavior.

Group permissions

Any user can remove themselves from a group, unless they are the only Owner of the group.

The following table lists the group permissions available for each role.

The Minimal Access role is not included because it has no permissions.

Groups

Group permissions for group features:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Browse group✓✓✓✓✓✓✓
Search projects in group✓✓✓✓✓✓✓
Search subgroups in group✓✓✓✓✓✓✓
View group audit events1✓✓✓✓
Create project in group2✓✓✓
Create subgroup3✓✓
Change custom settings for project integrations✓
Edit epic comments (posted by any user)✓✓
Fork project into a group✓✓
View Billing4✓
View group Usage quotas page4✓
Migrate group✓
Archive group✓
Delete group✓
Transfer group✓
Manage subscriptions, storage, and compute minutes✓
Manage group access tokens✓
Change group visibility level✓
Edit group settings✓
Configure project templates✓
Configure SAML SSO4✓
Disable notification emails✓
Import project✓✓

Group analytics

Group permission for analytics features including value streams, product analytics, and insights:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View GitLab Duo and SDLC trends✓✓✓✓✓
View insights✓✓✓✓✓✓✓
View insights charts✓✓✓✓✓✓✓
View issue analytics✓✓✓✓✓✓✓
View contribution analytics✓✓✓✓✓✓✓
View value stream analytics✓✓✓✓✓
View productivity analytics✓✓✓✓✓
View group DevOps adoption✓✓✓✓✓
View metrics dashboard annotations✓✓✓✓✓
Manage metrics dashboard annotations✓✓✓

Group application security

Group permissions for Application Security features including dependency management, security analyzers, security policies, and vulnerability management.

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View dependency list✓✓✓✓
View vulnerability report✓✓✓✓
View security dashboard✓✓✓✓
Create security policy project✓✓
Assign security policy project✓✓

Group Secrets Manager

Group permissions for GitLab Secrets Manager:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Enable GitLab Secrets Manager5✓
Manage permissions for secrets✓
Read secret metadata✓
Create, update, and delete secrets6✓
Create secrets (without update permission)6✓
Read secret value7

Group CI/CD

Group permissions for CI/CD features including runners, variables, and protected environments:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View instance runner✓✓✓✓✓✓✓
View group runners✓✓
Manage group-level Kubernetes cluster✓✓
Manage group runners✓
Manage group level CI/CD variables✓
Manage group protected environments✓

Group compliance

Group permissions for compliance features including compliance center, audit events, compliance frameworks, and licenses.

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View audit events8✓✓✓✓
View licenses in dependency list✓✓✓✓
View compliance center✓✓
Manage compliance frameworks✓✓
Assign compliance frameworks to projects✓✓
Manage audit streams✓✓

Group GitLab Duo

Group permissions for GitLab Duo:

ActionNon-memberGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Use GitLab Duo features9✓✓✓✓✓✓✓
Configure GitLab Duo feature availability✓✓
Configure GitLab Duo Self Hosted✓
Enable beta and experimental features✓
Purchase GitLab Duo seats✓

Group packages and registries

Group permissions for the package and container registry:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Pull container registry images10✓✓✓✓✓✓✓
Pull container images with the dependency proxy✓✓✓✓✓✓✓
Delete container registry images✓✓✓
Configure a virtual registry✓✓
Pull an artifact from a virtual registry✓✓✓✓✓✓

Group permissions for package registry:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Pull packages✓✓✓✓✓
Publish packages✓✓✓
Delete packages✓✓
Manage package settings✓
Manage dependency proxy cleanup policies✓
Enable dependency proxy✓
Disable dependency proxy✓
Purge the group dependency proxy✓
Enable package request forwarding✓
Disable package request forwarding✓

Group planning

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View epic✓✓✓✓✓✓✓
Search epics11✓✓✓✓✓✓✓
Add issues to an epic12✓✓✓✓✓✓✓
Add child epics13✓✓✓✓✓✓✓
Add parent epic14✓✓✓✓✓✓✓
Add internal notes✓✓✓✓✓✓
Create epics✓✓✓✓✓✓
Update epic details✓✓✓✓✓✓
Manage epic boards✓✓✓✓✓✓
Delete epics15✓✓✓✓✓✓✓

Group permissions for wikis:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View group wiki16✓✓✓✓✓✓✓
Search group wikis17✓✓✓✓✓✓✓
Create group wiki pages✓✓✓✓
Edit group wiki pages✓✓✓✓
Delete group wiki pages✓✓✓✓

Group repositories

Group permissions for repository features including merge requests, push rules, and deploy tokens.

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Manage deploy tokens✓
Manage merge request settings✓
Manage push rules✓

Group user management

Group permissions for user management:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View 2FA status of members✓
Filter members by 2FA status✓
Manage group members✓
Manage group-level custom roles✓
Share (invite) groups to groups✓

Group workspaces

Groups permissions for workspaces:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View workspace cluster agents mapped to a group✓✓
Map or unmap workspace cluster agents to and from a group✓

Project permissions

A user’s role determines what permissions they have on a project. The Owner role provides all permissions but is available only:

  • For group and project Owners.
  • For Administrators.

Personal namespace owners:

  • Are displayed as having the Maintainer role on projects in the namespace, but have the same permissions as a user with the Owner role.
  • For new projects in the namespace, are displayed as having the Owner role.

When you configure protected branch settings, selecting a role grants access to users with that role and all higher roles. For example, if you select Maintainers in the protected branch settings, users with both the Maintainer and Owner roles can perform the action.

For more information about how to manage project members, see members of a project.

The following table lists the project permissions available for each role.

The Minimal Access role is not included because it has no permissions.

Projects

Project permissions for project features:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Download project18✓✓✓✓✓✓✓
Leave comments✓✓✓✓✓✓✓
Reposition comments on images (posted by any user)19✓✓✓✓✓✓✓
View insights✓✓✓✓✓✓✓
View requirements✓✓✓✓✓✓✓
View time tracking reports18✓✓✓✓✓✓✓
View snippets✓✓✓✓✓✓✓
Search snippets and comments✓✓✓✓✓✓✓
View project traffic statistics✓✓✓✓✓
Create snippets✓✓✓✓✓
View releases20✓✓✓✓✓✓
Manage releases21✓✓
Configure webhooks✓✓
Manage project access tokens22✓✓
Export project✓✓
Rename project✓✓
Edit project badges✓✓
Edit project settings✓✓
Change project features visibility level23✓✓
Change custom settings for project integrations✓✓
Edit comments posted by other users✓✓
Add deploy keys✓✓
Manage project operations✓✓
View Usage quotas page✓✓
Globally delete snippets✓✓
Globally edit snippets✓✓
Archive project✓
Change project visibility level✓
Delete project✓
Disable notification emails✓
Transfer project✓

Project permissions for GitLab Pages:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View GitLab Pages protected by access control✓✓✓✓✓✓✓
Manage GitLab Pages✓✓
Manage GitLab Pages domain and certificates✓✓
Remove GitLab Pages✓✓

Project analytics

Project permissions for analytics features including value streams, usage trends, product analytics, and insights.

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View issue analytics✓✓✓✓✓✓✓
View value stream analytics✓✓✓✓✓
View CI/CD analytics✓✓✓✓✓
View code review analytics✓✓✓✓✓
View DORA metrics✓✓✓✓✓
View merge request analytics✓✓✓✓✓
View repository analytics✓✓✓✓✓
View Value Streams Dashboard✓✓✓✓✓
View GitLab Duo and SDLC trends✓✓✓✓✓

Project application security

Project permissions for application security features including dependency management, security analyzers, security policies, and vulnerability management.

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View dependency list✓✓✓✓
View licenses in dependency list✓✓✓✓
View security dashboard✓✓✓✓
View vulnerability report✓✓✓✓
Create vulnerability manually✓✓✓
Create issue from vulnerability finding✓✓✓✓
Create on-demand DAST scans✓✓✓✓
Run on-demand DAST scans✓✓✓✓
Create individual security policies✓✓✓
Change individual security policies✓✓✓
Delete individual security policies✓✓✓
Create CVE ID request✓✓
Change vulnerability status24✓✓✓
Create security policy project✓
Assign security policy project✓
Configure SAST vulnerability resolution25✓✓✓
Configure SAST false positive detection25✓✓✓
Configure Secret detection false positive detection25✓✓✓
Manage other security configurations26✓✓✓

Project Secrets Manager

Project permissions for GitLab Secrets Manager:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View Secrets Manager user permissions✓✓
Manage permissions for secrets✓
Read secrets metadata27, 28✓✓
Create and update secrets27, 28✓✓
Create secrets (without update permission)27✓
Delete secrets27✓
Read secret value29

Project CI/CD

GitLab CI/CD permissions for some roles can be modified by these settings:

Project Owners can perform any listed action, and can delete pipelines:

ActionNon-memberGuestPlannerReporterSecurity ManagerDeveloperMaintainer
View instance runner✓✓✓✓✓✓✓
View existing artifacts30✓✓✓✓✓✓✓
View list of jobs31✓✓✓✓✓✓✓
View artifacts32✓✓✓✓✓✓✓
Download artifacts32✓✓✓✓✓✓✓
View environments30✓✓✓✓✓✓✓
View job logs and job details page31✓✓✓✓✓✓✓
View pipelines and pipeline details pages31✓✓✓✓✓✓✓
View pipelines tab in MR30✓✓✓✓✓✓✓
View vulnerabilities in a pipeline33✓✓✓✓✓✓
Run deployment job for a protected environment34✓✓✓
View agents for Kubernetes✓✓
View project Secure Files✓✓
Download project Secure Files✓✓
View a job with debug logging✓✓
Create environments✓✓
Delete environments✓✓
Stop environments✓✓
Run, rerun, or retry CI/CD pipeline or job35✓✓✓
Run, rerun, or retry CI/CD pipeline or job for a protected branch36✓✓
Delete job logs or job artifacts37✓✓
Enable review apps✓✓
Cancel jobs38✓✓
Read Terraform state✓✓
Run interactive web terminals39✓✓
Use pipeline editor✓✓
View project runners40✓✓
Manage project runners40✓
Delete project runners41✓
Manage agents for Kubernetes✓
Manage CI/CD settings✓
Manage job triggers✓
Manage project CI/CD variables✓
Manage project protected environments✓
Manage project Secure Files✓
Manage Terraform state✓
Add project runners to project42✓
Clear runner caches manually✓
Enable instance runners in project✓
Create pipeline schedules43✓✓
Edit own pipeline schedules43✓✓
Delete own pipeline schedules✓✓
Run pipeline schedules manually44✓✓
Take ownership of pipeline schedules✓
Delete others’ pipeline schedules✓

This table shows granted privileges for jobs triggered by specific roles.

Project Owners can do any listed action, but no users can push source and LFS together. Guest users and members with the Reporter role cannot do any of these actions.

ActionDeveloperMaintainer
Clone source and LFS from current project✓✓
Clone source and LFS from public projects✓✓
Clone source and LFS from internal projects45✓✓
Clone source and LFS from private projects46✓✓
Pull container images from current project✓✓
Pull container images from public projects✓✓
Pull container images from internal projects45✓✓
Pull container images from private projects46✓✓
Push container images to current project47✓✓

Project compliance

Project permissions for compliance features including compliance center, audit events, compliance frameworks, and licenses.

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View allowed and denied licenses in MR48✓✓✓✓✓✓✓
View audit events49✓✓✓✓
View licenses in dependency list✓✓✓✓
View compliance center✓✓
Manage audit streams✓

Project GitLab Duo

Project permissions for GitLab Duo:

ActionNon-memberGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Use GitLab Duo features50✓✓✓✓✓✓✓
Configure GitLab Duo feature availability✓✓

Project merge requests

Project permissions for merge requests:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View a merge request51✓✓✓✓✓✓✓
Search merge requests and comments51✓✓✓✓✓✓✓
Approve merge requests52✓✓✓✓✓✓
Add internal note✓✓✓✓✓✓
Comment and add suggestions✓✓✓✓✓✓
Create snippets✓✓✓✓✓
Create merge request53✓✓✓
Update merge request details54✓✓✓
Manage merge request settings✓✓
Manage merge request approval rules✓✓
Delete merge request✓

Project model registry and experiments

Project permissions for model registry and model experiments.

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View models and versions55✓✓✓✓✓✓✓
View model experiments56✓✓✓✓✓✓✓
Create models, versions, and artifacts57✓✓✓
Edit models, versions, and artifacts✓✓✓
Delete models, versions, and artifacts✓✓✓
Create experiments and candidates✓✓✓
Edit experiments and candidates✓✓✓
Delete experiments and candidates✓✓✓

Project monitoring

Project permissions for monitoring including error tracking and incident management:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View an incident✓✓✓✓✓✓✓
Assign an incident management alert✓✓✓✓✓✓✓
Participate in on-call rotation for Incident Management✓✓✓✓✓✓✓
View alerts✓✓✓✓✓
View error tracking list✓✓✓✓✓
View escalation policies✓✓✓✓✓
View on-call schedules✓✓✓✓✓
Create incident✓✓✓✓✓
Manage incident metric images✓✓✓✓✓
Change alert status✓✓✓✓✓
Change incident severity✓✓✓✓✓
Change incident escalation status✓✓✓
Change incident escalation policy✓✓✓
Change error status✓✓✓
Manage error tracking✓✓
Manage escalation policies✓✓
Manage on-call schedules✓✓

Project packages and registries

Project permissions for container registry:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Pull container registry images58✓✓✓✓✓✓✓
Push container registry images✓✓✓
Delete container registry images✓✓✓
Manage cleanup policies✓✓
Create tag protection rules✓✓
Create immutable tag protection rules✓

Project permissions for package registry:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
Pull packages59✓✓✓✓✓✓✓
Publish packages✓✓✓
Delete packages✓✓
Delete files associated with a package✓✓

Project planning

Project permissions for issues:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View issues✓✓✓✓✓✓✓
Search issues and comments✓✓✓✓✓✓✓
Create issues✓✓✓✓✓✓✓
View confidential issues✓✓✓✓✓✓
Search confidential issues and comments✓✓✓✓✓✓
Edit issues, including metadata and item locking60✓✓✓✓✓✓
Resolve threads on issues61✓✓✓
Add internal notes✓✓✓✓✓✓
Close and reopen issues62✓✓✓✓✓✓
Manage design management files✓✓✓✓✓✓
Manage issue boards✓✓✓✓✓✓
Manage milestones✓✓✓✓✓✓
Search milestones✓✓✓✓✓✓
Archive or reopen requirements63✓✓✓✓✓✓
Create or edit requirements64✓✓✓✓✓✓
Import or export requirements✓✓✓✓✓✓
Archive test cases✓✓✓✓✓✓
Create test cases✓✓✓✓✓✓
Move test cases✓✓✓✓✓✓
Reopen test cases✓✓✓✓✓✓
Import issues from a CSV file✓✓✓✓✓✓
Export issues to a CSV file✓✓✓✓✓✓✓
Delete issues65✓✓✓✓✓✓
Manage Feature flags✓✓✓

Project permissions for tasks:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View tasks✓✓✓✓✓✓✓
Search tasks✓✓✓✓✓✓✓
Create tasks✓✓✓✓✓✓✓
Edit tasks, including metadata and item locking66✓✓✓✓✓✓
Resolve threads on tasks67✓✓✓
Add a linked item✓✓✓✓✓✓✓
Convert to another item type✓✓✓✓✓✓
Remove from issue✓✓✓✓✓✓✓
Add internal note✓✓✓✓✓✓
Delete tasks68✓✓✓✓✓✓✓

Project permissions for OKRs:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View OKRs✓✓✓✓✓✓✓
Search OKRs✓✓✓✓✓✓✓
Create OKRs✓✓✓✓✓✓✓
Edit OKRs, including metadata and item locking✓✓✓✓✓✓✓
Resolve threads on OKRs69✓✓✓
Add a child OKR✓✓✓✓✓✓✓
Add a linked item✓✓✓✓✓✓✓
Convert to another item type✓✓✓✓✓✓✓
Edit OKRs✓✓✓✓✓✓
Change confidentiality in OKR✓✓✓✓✓✓
Add internal note✓✓✓✓✓✓

Project permissions for wikis:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View wiki✓✓✓✓✓✓✓
Search wikis✓✓✓✓✓✓✓
Create wiki pages✓✓✓✓
Edit wiki pages✓✓✓✓
Delete wiki pages✓✓✓✓

Project repositories

Project permissions for repository features including source code, branches, push rules, and more:

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View project code70✓✓✓✓✓✓✓
Search project code70✓✓✓✓✓✓✓
Search commits and comments70✓✓✓✓✓✓✓
Pull project code71✓✓✓✓✓✓✓
View commit status✓✓✓✓✓
Create commit status72✓✓✓
Update commit status72✓✓✓
Create Git tags✓✓✓
Delete Git tags✓✓✓
Create new branches✓✓✓
Push to non-protected branches✓✓✓
Force push to non-protected branches✓✓✓
Delete non-protected branches✓✓✓
Manage protected branches✓✓
Push to protected branches72✓✓
Delete protected branches✓✓
Manage protected tags✓✓
Manage push rules✓✓
Remove fork relationship✓
Force push to protected branches73

Project user management

Project permissions for user management.

ActionGuestPlannerReporterSecurity ManagerDeveloperMaintainerOwner
View 2FA status of members✓✓
Manage project members74✓✓
Share (invite) projects with groups75✓

Subgroup permissions

When you add a member to a subgroup, they inherit the membership and permission level from the parent groups. This model allows access to nested groups if you have membership in one of its parents.

For more information, see subgroup memberships.

Users with Minimal Access

  • Tier: Premium, Ultimate
  • Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated

Users with the Minimal Access role do not:

  • Automatically have access to projects and subgroups in that top-level group. Owners must explicitly add these users to the specific subgroups and projects.
  • Count as licensed seats, provided the user has no other role anywhere on the instance or in the GitLab.com namespace.

The Minimal Access role grants none of the permissions in the group and project permission tables. Users with only this role cannot view project features such as wikis, issues, or the repository. To give these users access to a project or subgroup, an Owner must add them with the Guest role or a higher role.

If a user with the Minimal Access role is granted a billable role in any project or subgroup, they consume a license seat based on their highest role.

You can use the Minimal Access role with SAML SSO for GitLab.com groups to control access to groups and projects in the group hierarchy. You can set the default role to Minimal Access for members automatically added to the top-level group through SSO.

  1. In the top bar, select Search or go to and find your group.
  2. In the left sidebar, select Settings > SAML SSO.
  3. From the Default membership role dropdown list, select Minimal Access.
  4. Select Save changes.

Minimal access users receive 404 errors

Because of an outstanding issue, a user with the Minimal Access role who signs in with standard web authentication receives a 404 error when accessing the parent group.

A user with the Minimal Access role who signs in with Group SSO is redirected to their groups dashboard rather than the parent group page. For known issues with the groups shown on that dashboard, see issue 506280 and issue 507968.

To work around the 404 error, give these users the Guest, Planner, Reporter, Security Manager, Developer, Maintainer, or Owner role to any project or subgroup in the parent group. Guest users consume a license seat in the Premium tier but do not in the Ultimate tier.


  1. Developers and Maintainers can view events based on their individual actions only. For more information, see the prerequisites. ↩︎

  2. Developers, Maintainers, and Owners: Only if the project creation role is set for the instance or for the group.
    Developers: Developers can push commits to the default branch of a new project only if the default branch protection is set to “Partially protected” or “Not protected”. ↩︎

  3. Maintainers: Only if users with the Maintainer role can create subgroups. ↩︎

  4. Does not apply to subgroups. ↩︎ ↩︎ ↩︎

  5. On GitLab.com, only a top-level group Owner can enable Secrets Manager for subgroups and projects. On GitLab Self-Managed, an administrator must enable it for the instance. ↩︎

  6. Owners can grant these actions to other roles, specific users, groups, or custom roles. See Manage secrets permissions. ↩︎ ↩︎

  7. No role can read a secret’s value. CI/CD jobs read values through job authentication. Other workloads read values through the Secrets Manager API, and only if they have been granted the read value permission for that secret. ↩︎

  8. Users can view events based on their individual actions only. For more details, see the prerequisites. ↩︎

  9. If the user has GitLab Duo Pro or Enterprise, the user must be assigned a seat to gain access to that GitLab Duo add-on. If the user has GitLab Duo Core, there are no other requirements. ↩︎

  10. Guests can only view events based on their individual actions. ↩︎

  11. You must have permission to view the epic. ↩︎

  12. You must have permission to view the epic and edit the issue. ↩︎

  13. You must have permission to view the parent and child epics. ↩︎

  14. You must have permission to view the parent epic. ↩︎

  15. Users who don’t have the Planner or Owner role can only delete the epics they authored. ↩︎

  16. Guests: In addition, if your group is public or internal, all users who can see the group can also see group wiki pages. ↩︎

  17. Guests: In addition, if your group is public or internal, all users who can see the group can also search group wiki pages. ↩︎

  18. On GitLab Self-Managed, users with the Guest role are able to perform this action only on public and internal projects (not on private projects). External users must be given explicit access (at least the Reporter role) even if the project is internal. Users with the Guest role on GitLab.com are only able to perform this action on public projects because internal visibility is not available. ↩︎ ↩︎

  19. Applies only to comments on Design Management designs. ↩︎

  20. Guest users can access GitLab Releases for downloading assets but are not allowed to download the source code nor see repository information like commits and release evidence. ↩︎

  21. If the tag is protected, this depends on the access given to Developers and Maintainers. ↩︎

  22. For GitLab Self-Managed, project access tokens are available in all tiers. For GitLab.com, project access tokens are supported in the Premium and Ultimate tier (excluding trial licenses). ↩︎

  23. A Maintainer or Owner can’t change project features visibility level if project visibility is set to private.

     ↩︎
  24. The admin_vulnerability permission was removed from the Developer role in GitLab 17.0. ↩︎

  25. Security Managers can configure these settings in Settings > General > GitLab Duo. ↩︎ ↩︎ ↩︎

  26. Security Managers can only manage other security configurations through the UI (Secure > Security configuration). ↩︎

  27. Users with the Owner role can grant these actions to other roles, specific users, groups, or custom roles. See Manage secrets permissions. ↩︎ ↩︎ ↩︎ ↩︎

  28. Users with the Maintainer role have this permission by default for secrets managers enabled in GitLab 19.4 and later. Users with the Owner role can remove or change the default permissions for the Maintainer role. ↩︎ ↩︎

  29. No role can read a secret’s value. CI/CD jobs read values through job authentication. Other workloads read values through the Secrets Manager API, and only if they have been granted the read value permission for that secret. ↩︎

  30. Non-members and guests: Only if the project is public. ↩︎ ↩︎ ↩︎

  31. Non-members: Only if the project is public and Project-based pipeline visibility is enabled.
    Guests: Only if Project-based pipeline visibility is enabled. ↩︎ ↩︎ ↩︎

  32. Non-members: Only if the project is public, Project-based pipeline visibility is enabled, and artifacts:public: false is not set on the job.
    Guests: Only if Project-based pipeline visibility is enabled and artifacts:public: false is not set on the job.
    Reporters: Only if artifacts:public: false is not set on the job.
    The artifacts:public setting only affects GitLab UI and API access. CI/CD job tokens can still access artifacts with the runner API. ↩︎ ↩︎

  33. Guests: Only if Project-based pipeline visibility is enabled. ↩︎

  34. Reporters: Only if the user is part of a group with access to the protected environment.
    Developers and maintainers: Only if the user is allowed to deploy to the protected environment. ↩︎

  35. Security Managers can only run DAST on-demand scan pipelines. ↩︎

  36. Developers and maintainers: Only if the user is allowed to merge or push to the protected branch. ↩︎

  37. Developers: Only if the job was triggered by the user and runs for a non-protected branch. ↩︎

  38. Cancellation permissions can be restricted in the pipeline settings. ↩︎

  39. Developers and Maintainers: Only if the job was triggered by the user.
    Administrators: Any job. If Admin Mode is enabled for the instance, administrators must turn on Admin Mode for their session. ↩︎

  40. Maintainers: Must have the Maintainer role for a project associated with the runner. ↩︎ ↩︎

  41. Maintainers: Must have the Maintainer role for the owner project (first project associated with runner). ↩︎

  42. Maintainers: Must have the Maintainer role for the project being added and for a project already associated with the runner. ↩︎

  43. Developers: Only for branches where the user has merge permissions. For protected branches, must have merge permissions for the target branch. For protected tags, the user must be allowed to create protected tags. These permission requirements apply when creating or editing schedules, and are checked dynamically as branch protection rules may change over time. ↩︎ ↩︎

  44. When running manually, the pipeline executes with the triggering user’s permissions instead of the schedule owner’s permissions. ↩︎

  45. Developers and Maintainers: Only if the triggering user is not an external user. ↩︎ ↩︎

  46. Only if the triggering user is a member of the project. See also Usage of private Docker images with if-not-present pull policy. ↩︎ ↩︎

  47. You cannot push container images to other projects. ↩︎

  48. On GitLab Self-Managed, users with the Guest role are able to perform this action only on public and internal projects (not on private projects). External users must have the Reporter, Developer, Maintainer, or Owner role, even if the project is internal. Users with the Guest role on GitLab.com are able to perform this action only on public projects because internal visibility is not available. ↩︎

  49. Users can only view events based on their individual actions. For more details, see the prerequisites. ↩︎

  50. Code Suggestions requires a user being assigned a seat to gain access to a GitLab Duo add-on. ↩︎

  51. On GitLab Self-Managed, users with the Guest role are able to perform this action only on public and internal projects (not on private projects). External users must be given explicit access (at least the Reporter role) even if the project is internal. Users with the Guest role on GitLab.com are only able to perform this action on public projects because internal visibility is not available. ↩︎ ↩︎

  52. Approval from Planner and Reporter roles is available only if enabled for the project. ↩︎

  53. In projects that accept contributions from external members, users can create, edit, and close their own merge requests. For private projects, this excludes the Guest role as those users cannot clone private projects. For internal projects, includes users with read-only access to the project, as they can clone internal projects. ↩︎

  54. In projects that accept contributions from external members, users can create, edit, and close their own merge requests. They cannot edit some fields, like assignees, reviewers, labels, and milestones. ↩︎

  55. Non-members can only view models and versions in public projects with the Everyone with access visibility level. Non-members can’t view internal projects, even if they’re logged in. ↩︎

  56. Non-members can only view model experiments in public projects with the Everyone with access visibility level. Non-members can’t view internal projects, even if they’re logged in. ↩︎

  57. You can also upload and download artifacts with the package registry API, which uses a different set of permissions. ↩︎

  58. Viewing the container registry and pulling images is controlled by container registry visibility permissions. The Guest role does not have viewing or pulling permissions in private projects. ↩︎

  59. On GitLab Self-Managed, users with the Guest role are able to perform this action only on public and internal projects (not on private projects). External users must be given explicit access (at least the Reporter role) even if the project is internal. Users with the Guest role on GitLab.com are only able to perform this action on public projects because internal visibility is not available. ↩︎

  60. Metadata includes labels, assignees, milestones, epics, weight, confidentiality, time tracking, and more. Guest users can only set metadata when creating an issue. They cannot change the metadata on existing issues. Guest users can modify the title and description of issues that they authored or are assigned to. ↩︎

  61. Users can resolve threads they started and threads on issues they authored. ↩︎

  62. Guest users can close and reopen issues that they authored or are assigned to. ↩︎

  63. Guest users can archive and reopen issues that they authored or are assigned to. ↩︎

  64. Guest users can modify the title and description that they authored or are assigned to. ↩︎

  65. Users who don’t have the Planner or Owner role can only delete the issues they authored. ↩︎

  66. Guest users can modify the title and description that they authored or are assigned to. ↩︎

  67. Users can resolve threads they started and threads on tasks they authored. ↩︎

  68. Users who don’t have the Planner or Owner role can only delete the tasks they authored. ↩︎

  69. Users can resolve threads they started and threads on OKRs they authored. ↩︎

  70. On GitLab Self-Managed, users with the Guest role are able to perform this action only on public and internal projects (not on private projects). External users must be given explicit access (at least the Planner role) even if the project is internal. Users with the Guest role on GitLab.com are only able to perform this action on public projects because internal visibility is not available. Users with the Guest role and an Ultimate license can view private repository content if an administrator (on GitLab Self-Managed or GitLab Dedicated) or group owner (on GitLab.com) gives those users permission. The administrator or group owner can create a custom role through the API or UI and assign that role to the users. In GitLab 18.7 and later, users with the Planner role can view private repository content. ↩︎ ↩︎ ↩︎

  71. If the branch is protected, this depends on the access given to Developers and Maintainers. ↩︎

  72. On GitLab Self-Managed, users with the Guest role are able to perform this action only on public and internal projects (not on private projects). External users must be given explicit access (at least the Reporter role) even if the project is internal. Users with the Guest role on GitLab.com are only able to perform this action on public projects because internal visibility is not available. Users with the Guest role and an Ultimate license can view private repository content if an administrator (on GitLab Self-Managed or GitLab Dedicated) or group owner (on GitLab.com) gives those users permission. The administrator or group owner can create a custom role through the API or UI and assign that role to the users. ↩︎ ↩︎ ↩︎

  73. Not allowed for Guest, Reporter, Developer, Maintainer, or Owner. See protected branches. ↩︎

  74. Maintainers cannot create, demote, or remove Owners, and they cannot promote users to the Owner role. They also cannot approve Owner role access requests. ↩︎

  75. When Share Group Lock is enabled the project can’t be shared with other groups. It does not affect group with group sharing. ↩︎