News
— In the age of AI-accelerated DevSecOps, internal governance is paramount. Control your team's access and fortify your security posture with our new Role-Based Permissions.

Last week, our team engaged with leaders at the IT Security & Legal Symposium. The central theme was clear, as development speeds up with tools like GitLab Duo and AI, the need for robust governance and auditability within the organization accelerates even faster.
At GitLabHost, our mission is to provide secure, compliant, managed hosting so you can focus on shipping code. This commitment to security extends beyond our infrastructure and into how you manage your resources with us.
That’s why we are excited to announce the launch of Role-Based Permissions (RBP) in the GitLabHost Control Panel. This critical update gives company owners and Administrators fine-grained control over exactly who can manage, purchase, and view sensitive data.
Before today, every user within your company profile in our Control Panel held the status of 'Admin.' While simple, this presented clear risks:
This 'all or nothing' approach is simply not compatible with modern security and compliance best practices. It directly violates the principle of least privilege, which is foundational to a secure environment.
We have split access into three distinct roles to ensure separation of duties and minimize potential risk:
- Admin: Full control over everything: instance creation/deletion, user management, billing, and mandates. (Equivalent to the previous access level.). This role would be perfect for: Company Owners, Technical Leads, or designated Security Administrators.
- Billing Access: strictly limited to viewing and managing invoices, billing information, and payment mandates. Cannot view or manage GitLab Instances or Runners. This role would be perfect for: Accounting, Finance, and Procurement Teams.
- Member: View-Only Access to practically everything, including existing GitLab instances and Runners. Cannot create, edit, delete, or manage billing. And this role could be used for: Developers, Project Managers, or Internal Teams requiring read-only status for auditing or information gathering.
While RBP enhances security, it's crucial to maintain operational resilience. We strongly recommend having at least two active users assigned the 'Admin' role within your company. This ensures that in the event an Administrator leaves the company, or if their account is otherwise inaccessible, you retain full access to your GitLabHost Control Panel and can manage your services without interruption.
The new Role-Based Permissions feature is live today. It is a direct result of our commitment to embedding security and governance into every aspect of our managed service.
We encourage all current Admins to review their user lists and assign the appropriate roles to enforce the principle of least privilege immediately.
Log in to your Control Panel now to manage user roles

Bastiaan
DevSecOps Engineer