New Aug 21, 2026

Fine-Grained Access Control Now Available for All Heroku Customers

Company/Startup Blogs All from Blog | Heroku View Fine-Grained Access Control Now Available for All Heroku Customers on heroku.com

Fine-Grained Access Controls is now available to all Heroku customers. Heroku’s legacy system gave you predefined roles like admin, member, or collaborator, each with a fixed bundle of permissions. It replaces that system with fine-grained roles like view, deploy, operate, and manage, with specific capability sets. Access control is managed at an app-specific layer, giving your team the capability to tune individual access for each of your apps.

Why Fine-Grained Access Control matters for your team

Tighter security and compliance controls

Static permission models force organizations into an all-or-nothing trade-off between developer velocity and system security. Fine-Grained Access Control eliminates this friction by bringing Partial Zero Trust Identity and Access Management (IAM) mechanics directly to Heroku resources. By scoping permissions to specific apps, pipelines, and roles, security teams can enforce precise guardrails without slowing down engineering workflows.

Greater team productivity

Managing user access shouldn’t rely on central IT ticket queues or administrative bottlenecks. Fine-Grained Access Control lets you grant everyday app permissions without handing over admin keys, making it easier to onboard new team members and keep application delivery moving while maintaining strict security boundaries.

How Fine-Grained Access Control works

Fine-Grained Access Control integrates directly into existing Heroku interfaces, allowing you to manage permissions, automate access via scripts, or synchronize roles with external identity providers.

1. Heroku Dashboard

The Heroku Dashboard offers an intuitive interface for viewing and managing team access across organizations, pipelines, and individual apps. Admins can audit member capabilities at a glance and update roles with precision.

2. Heroku CLI

Manage permissions directly from your terminal using standard Heroku CLI commands. Command-line access allows platform teams to integrate permission updates into existing automation scripts and onboarding pipelines.

Note: Heroku CLI v11.10.0 or later is required, please update if you are on an earlier version.

# View assigned capabilities for a specific application
$ heroku access --app my-app
  email                       role            permissions
──────────────────────────────────────────────────────────────────────────────
  admin@company.com           admin           deploy, manage, operate, view
  existing-user@company.com   collaborator    operate, view

# Add a new team member to your app with operate and view permissions $ heroku access:add user@company.com --app my-app --permissions operate,view Adding user@company.com in application β¬’ my-app with operate,view permissions… done

# Update permissions of an existing team member on your app $ heroku access:update existing-user@company.com --app my-app --permissions deploy,manage Updating existing-user@company.com in application β¬’ my-app with deploy,manage permissions… done

3. Heroku Platform API

Build custom internal identity tools or integrate Heroku permission workflows into centralized identity providers (IdPs) like Okta, Microsoft Entra ID, or Ping Identity. The Platform API exposes endpoints to programmatically assign, update, and revoke capabilities across your entire Heroku footprint.

Getting started with Fine-Grained Access Control

If you’re already using Heroku, your existing permissions have been automatically migrated to the new model. You don’t need to do anything. Your team’s access continues to work exactly as before.
To start taking advantage of the advanced features:

  1. If using the Heroku CLI, check your version: Use heroku --version to verify you are on v11.10.0 or later.
  2. Review your current permissions: Understand what access your team members have.
  3. Identify opportunities to refine access: Look for cases where permissions can be more precise.
  4. Update team member roles: Adjust access levels to match actual responsibilities.

To learn more, check out our Dev Center documentation. Have questions about Fine-Grained Access Control? Contact Heroku Support.

The post Fine-Grained Access Control Now Available for All Heroku Customers appeared first on Heroku.

Scroll to top