Skip Navigation
Heroku Dev Center Dev Center
  • Get Started
  • Documentation
  • Changelog
  • Search
Heroku Dev Center Dev Center
  • Get Started
    • Node.js
    • Ruby on Rails
    • Ruby
    • Python
    • Java
    • PHP
    • Go
    • Scala
    • Clojure
    • .NET
  • Documentation
  • Changelog
  • More
    Additional Resources
    • Home
    • Elements
    • Products
    • Pricing
    • Careers
    • Help
    • Status
    • Events
    • Podcasts
    • Compliance Center
    Heroku Blog

    Heroku Blog

    Find out what's new with Heroku on our blog.

    Visit Blog
  • Log in or Sign up
Show nav
View categories

Categories

  • Heroku Architecture
    • Compute (Dynos)
      • Dyno Management
      • Dyno Concepts
      • Dyno Behavior
      • Dyno Reference
      • Dyno Troubleshooting
    • Stacks (operating system images)
    • Networking & DNS
    • Platform Policies
    • Buildpacks
    • Platform Principles
  • Developer Tools
    • AI Tools
    • Command Line
    • Heroku VS Code Extension
  • Deployment
    • Deploying with Git
    • Deploying with Docker
    • Deployment Integrations
  • Continuous Delivery & Integration (Heroku Flow)
    • Continuous Integration
  • Language Support
    • Node.js
      • Troubleshooting Node.js Apps
      • Working with Node.js
      • Node.js Behavior in Heroku
    • Ruby
      • Rails Support
        • Working with Rails
      • Working with Bundler
      • Working with Ruby
      • Ruby Behavior in Heroku
      • Troubleshooting Ruby Apps
    • Python
      • Working with Python
      • Background Jobs in Python
      • Python Behavior in Heroku
      • Working with Django
    • Java
      • Java Behavior in Heroku
      • Working with Java
      • Working with Maven
      • Working with Spring Boot
      • Troubleshooting Java Apps
    • PHP
      • PHP Behavior in Heroku
      • Working with PHP
    • Go
      • Go Dependency Management
    • Scala
    • Clojure
    • .NET
      • Working with .NET
  • Databases & Data Management
    • Heroku Postgres
      • Postgres Basics
      • Postgres Getting Started
      • Postgres Performance
      • Postgres Data Transfer & Preservation
      • Postgres Availability
      • Postgres Special Topics
      • Heroku Postgres Advanced (Limited GA)
      • Migrating to Heroku Postgres
    • Heroku Key-Value Store
    • Apache Kafka on Heroku
    • Other Data Stores
  • AI
    • Inference Essentials
    • Inference API
    • Inference Quick Start Guides
    • AI Models
    • Tool Use
    • AI Integrations
    • Vector Database
  • Monitoring & Metrics
    • Logging
  • App Performance
  • Add-ons
    • All Add-ons
  • Collaboration
  • Security
    • App Security
    • Identities & Authentication
      • Single Sign-on (SSO)
    • Private Spaces
      • Infrastructure Networking
    • Compliance
  • Heroku Enterprise
    • Enterprise Accounts
    • Enterprise Teams
  • Patterns & Best Practices
  • Extending Heroku
    • Platform API
    • App Webhooks
    • Heroku Labs
    • Building Add-ons
      • Add-on Development Tasks
      • Add-on APIs
      • Add-on Guidelines & Requirements
    • Building CLI Plugins
    • Developing Buildpacks
    • Dev Center
  • Accounts & Billing
  • Troubleshooting & Support
  • Integrating with Salesforce
    • Heroku AppLink
      • Heroku AppLink Reference
      • Getting Started with Heroku AppLink
      • Working with Heroku AppLink
    • Heroku Connect (Salesforce sync)
      • Heroku Connect Administration
      • Heroku Connect Reference
      • Heroku Connect Troubleshooting
    • Other Salesforce Integrations
  • Collaboration
  • Understanding Heroku User Roles and Permissions

Understanding Heroku User Roles and Permissions

Table of Contents [expand]

  • Enterprise Account Permissions
  • Team Roles
  • App Permissions
  • Pipeline Permissions
  • How Roles and Permissions Work Together
  • Additional Reading

Last updated August 20, 2026

This article explains how roles and permissions work together across Heroku teams, apps, and pipelines. Understanding these relationships helps you manage access securely and efficiently.

Heroku uses a layered approach to access control. Each team, app, and pipeline, has its own roles and permissions. If you use Heroku Enterprise, there’s an additional account layer that provides advanced permission controls.

Enterprise Account Permissions

If you’re part of a Heroku Enterprise account, you have access to advanced permission controls at the organization level. Use these permissions to manage access to apps, pipelines, and resources across your entire enterprise.

See Enterprise Accounts Permissions Summary for details.

Team Roles

Many users interact with Heroku through teams. Teams assign roles that define what you can do across all associated apps and resources:

  • Admins: Full control over team settings, billing, and app management.
  • Members: Can create and manage apps, but have limited team settings access.
  • Viewer: Can view apps, pipelines, spaces, users, and resources.
  • Collaborators: Invited to specific apps, not the whole team.

Learn more in Team Roles and Allowed Actions and Managing Heroku Team Roles and App Access.

App Permissions

Each app has its own set of permissions, which are based on your team role or collaborator status. App permissions control actions like deploying code, managing config vars, and viewing logs.

For details, see App Permissions and Managing App Permissions.

Pipeline Permissions

Pipelines group apps into stages (development, staging, production) for continuous delivery. Pipeline permissions are distinct from app permissions and focus on actions related to review apps and CI.

  • Only pipeline owners (for personal accounts) or admins (for teams) can modify pipeline-level permissions.
  • Permissions include view, deploy, operate, and manage, each granting specific capabilities.

For a full breakdown, see Pipelines: Permissions and Capabilities.

Pipeline permissions don’t override app permissions. You need the right app-level access to perform certain actions, even if you have pipeline permissions.

How Roles and Permissions Work Together

  • Your team role sets your baseline access.
  • App permissions can further restrict or expand what you can do within a specific app.
  • Pipeline permissions control your ability to manage review apps, CI, and promotion flows within a pipeline.
  • Enterprise account permissions (if applicable) provide additional controls for large organizations.

For example, a team member with operate permission on a pipeline can manage review apps, but can’t deploy to production unless they also have deploy access on the production app.

Additional Reading

  • Team Roles and Allowed Actions
  • Managing Heroku Team Roles and App Access
  • App Permissions
  • Managing App Permissions
  • Pipelines: Permissions and Capabilities
  • Managing Access in Enterprise Accounts (Enterprise only)

Feedback

Log in to submit feedback.

Information & Support

  • Getting Started
  • Documentation
  • Changelog
  • Compliance Center
  • Training & Education
  • Blog
  • Support Channels
  • Status

Language Reference

  • Node.js
  • Ruby
  • Java
  • PHP
  • Python
  • Go
  • Scala
  • Clojure
  • .NET

Other Resources

  • Careers
  • Elements
  • Products
  • Pricing
  • RSS
    • Dev Center Articles
    • Dev Center Changelog
    • Heroku Blog
    • Heroku News Blog
    • Heroku Engineering Blog
  • Twitter
    • Dev Center Articles
    • Dev Center Changelog
    • Heroku
    • Heroku Status
  • Github
  • LinkedIn
  • © 2026 Salesforce, Inc. All rights reserved. Various trademarks held by their respective owners. Salesforce Tower, 415 Mission Street, 3rd Floor, San Francisco, CA 94105, United States
  • heroku.com
  • Legal
  • Terms of Service
  • Privacy Information
  • Responsible Disclosure
  • Trust
  • Contact
  • Cookie Preferences
  • Your Privacy Choices