feat: promote MinimumImplicitMember experiment to GA (#27472)

Promotes the `minimum-implicit-member` experiment to GA and removes it.

## What changes

- The `minimum-implicit-member` experiment constant, its
`RoleOptions.MinimumImplicitMember` toggle, and the global
`rbac.MinimumImplicitMember()` accessor are deleted. The minimal-member
behavior is now the only behavior: `organization-member` and
`organization-service-account` carry only the floor (read-self records,
notifications, and similar) and grant **no workspace permissions**.
Workspace access lives exclusively on the
`organization-workspace-access` role.
- The experiment gate on customizing `default_org_member_roles` (`PATCH
/organizations/{org}`) is removed; the built-in-roles-only validation
remains.
- The dashboard's Default Roles section and the implied-roles display on
the members page are no longer experiment-gated.
- Admin docs: new "Default member roles" section in
`docs/admin/users/organizations.md`, cross-linked from
`groups-roles.md`.

## Why this is safe for existing deployments

Migration `000516` (shipped earlier) backfilled
`default_org_member_roles` with `['organization-workspace-access']` on
every organization. Members therefore keep exactly the effective
permissions they had with the experiment off; the workspace elevation
flows through the default role instead of being baked into
`organization-member`.

**Rollback caveat:** rolling back past this release restores the bundled
elevation, silently re-granting workspace access to members of
organizations that cleared their default roles.

## Review

Deep-review R1 findings are addressed in `chore: address deep-review
findings` (copy fixes, read-only Default Roles for viewers, removable
overlapping explicit grants, RBAC prose restoration, test
de-tautologizing, docs). Point-by-point disposition is in the PR
comments.

---

Generated by Coder Agents on behalf of @Emyrk.
This commit is contained in:
Steven Masley
2026-08-03 15:56:56 -05:00
committed by GitHub
parent fe4a73f8ab
commit 52423eb87b
24 changed files with 189 additions and 268 deletions
+5
View File
@@ -31,6 +31,11 @@ Roles determine which actions users can take within the platform.
A user may have one or more roles. All users have an implicit Member role that
may use personal workspaces.
Whether organization members can create and use workspaces is controlled per
organization through its default member roles. See
[Default member roles](./organizations.md#default-member-roles) for how to
remove workspace operations from the default member set.
## Custom Roles
> [!NOTE]
+32
View File
@@ -120,6 +120,38 @@ their organization. Users can be in multiple organizations.
![Workspace List](../../images/admin/users/organizations/workspace-list.png)
## Default member roles
> [!NOTE]
> Editing default member roles requires a Premium license.
> ([learn more](https://coder.com/pricing#compare-plans)).
Each organization carries a `default_org_member_roles` list of built-in role
names. Coder unions this list into every member's effective roles at request
time, so changes propagate to all current and future members on their next
request without re-issuing tokens or editing per-user role assignments.
The default value is `["organization-workspace-access"]`. With that default,
every organization member can read, build, ssh into, and execute commands in
workspaces they own. Removing `organization-workspace-access` from the list
creates organization members that cannot create or use workspaces unless the
role is assigned to them directly, which is useful for restricted accounts
that should only hold the minimal member permissions.
To edit the default roles in the dashboard, go to
**Admin settings** > **Organizations** > **Roles** > **Default Roles**, or
set `default_org_member_roles` via
`PATCH /organizations/{organization}`.
### Limitations
- `default_org_member_roles` accepts built-in role names only. Custom
organization roles are rejected; assign them directly to members instead.
- Removing a role from the list removes it from every member that does not
hold the role through a direct assignment, including existing members.
Review the per-organization [audit log](../security/audit-logs.md) if you
need to trace who changed the defaults.
## Next steps
- [Organizations - best practices](../../tutorials/best-practices/organizations.md)