API ReferenceChangelog
Legion APIECN SDK
API Reference

Admin Guide

User accounts are managed within Orion, which serves as the user interface for the Legion API.


Top-Level Administrative Account Role Definitions

Select a User Type for least privilege level. An admin account is the most privileged account with complete control over your organization's Legion instance.

Role NamePermissions & OperationsOperational Scope
AdminCan perform Org Management, manage Entities, Feeds, Tasks, and Integrations.High-level system configuration and user oversight.
MemberView and edit data from organizations they are part of; No Org Management.Operational data management within a specific scope. Auditing and monitoring only.

Admin Account Lifecycle Procedures

Admin account provisioning

New admin accounts should be created via the "Add User" interface using an organization-approved email domain. Providers should set all initial settings to recommended secure defaults upon provisioning.

Multi-factor Authentication(MFA)

MFA is mandatory for all account levels. MFA methods are defined at the organization level. Depending on your organization and the cloud location of where the Legion instance resides on MFA methods may include, but are not limited to, FIDO2/WebAuthn hardware keys (e.g., YubiKey) and PKI-based authentication (PIV/CAC cards).

Configuration

Once the organization is established by the Picogrid System Administrator, they will also create an owner/primary admin account. This owner/primary admin is granted the authority to manage user access, including adding or removing users and assigning administrative roles.

Decommissioning

Use the Remove user (trash can icon) to revoke access immediately upon a user's departure or role change. Revocation must be timely to prevent unauthorized access.

Security Settings Reference Table

The table below describes settings that only top-level admins can control.

Setting NameAssociated FunctionSecurity ImpactRecommended Value
Org ManagementGrants the ability to add/remove users and change roles.Critical: High risk of unauthorized privilege escalation.Restricted to < 3 users.
IntegrationsManages external API and service connections.High: Risk of data exfiltration to unauthorized third parties.Enabled only for vetted services.