> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nx1cloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set a member's workspace roles

> Replace a member's roles in this workspace.

The submitted list is the complete set — send an empty list to
revoke all access. Requires a Keycloak session; PSK credentials
cannot change who has access.

**Required roles**: `workspace_admin` or `nx1_decisions_admin`



## OpenAPI

````yaml put /api/decisions/{workspace}/members/{subject}
openapi: 3.1.0
info:
  title: Nx1 AI API
  description: |

    AI API for Nx1 Data Platform Management and Automated Data Tasks.

    Authentication is required via PSK in Authorization header.

    Default PSK is | [ask a friend] |
  version: 0.10.2
servers: []
security: []
paths:
  /api/decisions/{workspace}/members/{subject}:
    put:
      tags:
        - Decisions
      summary: Set a member's workspace roles
      description: |-
        Replace a member's roles in this workspace.

        The submitted list is the complete set — send an empty list to
        revoke all access. Requires a Keycloak session; PSK credentials
        cannot change who has access.

        **Required roles**: `workspace_admin` or `nx1_decisions_admin`
      operationId: set_member_roles_api_decisions__workspace__members__subject__put
      parameters:
        - name: workspace
          in: path
          required: true
          schema:
            type: string
            maxLength: 64
            pattern: ^[a-z0-9][a-z0-9-]{0,63}$
            description: Workspace slug.
            title: Workspace
          description: Workspace slug.
        - name: subject
          in: path
          required: true
          schema:
            type: string
            description: Keycloak username to grant roles to.
            title: Subject
          description: Keycloak username to grant roles to.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MemberGrantRequest'
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MemberListResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
        '503':
          description: Service Unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - OAuth2AuthorizationCodeBearer: []
        - APIKeyHeader: []
components:
  schemas:
    MemberGrantRequest:
      properties:
        roles:
          items:
            $ref: '#/components/schemas/DecisionWorkspaceRoleEnum'
          type: array
          title: Roles
          description: >-
            Complete set of roles for this subject in this workspace. Replaces
            any existing grants — send an empty list to revoke.
      type: object
      required:
        - roles
      title: MemberGrantRequest
    MemberListResponse:
      properties:
        workspace:
          type: string
          title: Workspace
        members:
          items:
            $ref: '#/components/schemas/MemberResponse'
          type: array
          title: Members
      type: object
      required:
        - workspace
        - members
      title: MemberListResponse
    ErrorResponse:
      properties:
        error:
          type: string
          title: Error
          description: A brief description of the error that occurred.
        code:
          type: integer
          title: Code
          description: The HTTP status code associated with the error.
          default: 500
      type: object
      required:
        - error
      title: ErrorResponse
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    DecisionWorkspaceRoleEnum:
      type: string
      enum:
        - workspace_admin
        - author
        - approver
        - simulator
        - viewer
      title: DecisionWorkspaceRoleEnum
      description: |-
        Per-workspace role grants.

        ``workspace_admin`` deliberately cannot approve: separation of duties
        is the point of the matrix, and approval requires a distinct
        ``approver`` identity.
    MemberResponse:
      properties:
        subject:
          type: string
          title: Subject
        roles:
          items:
            $ref: '#/components/schemas/DecisionWorkspaceRoleEnum'
          type: array
          title: Roles
        granted_by:
          type: string
          title: Granted By
        granted_at:
          type: string
          format: date-time
          title: Granted At
      type: object
      required:
        - subject
        - roles
        - granted_by
        - granted_at
      title: MemberResponse
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    OAuth2AuthorizationCodeBearer:
      type: oauth2
      flows:
        authorizationCode:
          scopes: {}
          authorizationUrl: >-
            https://sso-rapid.rapid.nx1cloud.com/realms/rapid/protocol/openid-connect/auth
          tokenUrl: >-
            https://sso-rapid.rapid.nx1cloud.com/realms/rapid/protocol/openid-connect/token
    APIKeyHeader:
      type: apiKey
      in: header
      name: Authorization-PSK

````