> ## Documentation Index
> Fetch the complete documentation index at: https://www.truefoundry.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Role binding manifest

> Grant a role on a resource to users, teams, virtual accounts, or agents with a role-binding manifest.

A role binding grants a **role** on a **resource** to one or more **subjects**. It is separate from the resource manifest, so you can change access without editing the resource.

Apply it with [`tfy apply`](/docs/using-tfy-apply), or with [Create or update a role binding](/docs/api-reference/role-bindings/create-or-update-a-role-binding). Re-applying the same `name` updates that binding.

```yaml theme={"dark"}
type: role-binding
name: ws-staging-editors
subjects:
  - type: user
    name: alice@example.com
  - type: team
    name: data-science
permissions:
  - resourceType: workspace
    resourceFqn: tfy-usea1-devtest:tfy-gateway-staging
    role: workspace-editor
```

| Field | Meaning |
| - | - |
| `name` | Binding id. 3–66 characters: start with a lowercase letter, then lowercase letters, digits, or hyphens, and end with a letter or digit. |
| `subjects[].type` | `user`, `team`, `virtualaccount`, or `agent`. |
| `subjects[].name` | Email when `type` is `user`. Otherwise the team, virtual account, or agent name. |
| `permissions[].resourceType` | Resource kind, such as `workspace`, `cluster`, `ml-repo`, or `provider-account`. |
| `permissions[].resourceFqn` | Fully qualified name of that resource. Copy it from the resource page. |
| `permissions[].role` | Role name for that resource type, such as `workspace-editor` or `provider-account-manager`. |

Use either **one subject and many permissions**, or **many subjects and one permission**. A binding cannot have many of both. To give several people several roles, split it into one binding per role.

To grant the same access from the UI, use **Access Control** on the resource. See [Manage User Roles & Permissions](/docs/platform/manage-user-roles-and-permissions).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.