# Role-based access control on ZopDay

> Every ZopDay surface (projects, environments, deployments, provisioning, spaces, and remediation) is now gated by the same permission engine that protects ZopNight. Buttons a user can't use are disabled with a clear tooltip, and restricted pages show a single access screen instead of leaking structure. The Overrides page now paginates and sorts at scale, and IAM import cleanly separates linked from newly imported users.

Source: https://zop.dev/changelog/v1-13-0
Published: 2026-05-27 · Tags: zopday, zopnight, rbac, iam

---

Same permission engine as ZopNight.

## New

- ZopDay: role-based access control across every surface, using the same permission engine as ZopNight; restricted mutations are disabled with an Ask your admin tooltip and restricted pages show a single Access restricted screen. No org-side reconfiguration required

## Improved

- ZopNight: the Overrides page under a schedule group now paginates and sorts server-side, so the full list pages through regardless of size
- ZopNight: Manage IAM now distinguishes linked existing users from newly imported users, with a new Roles section and a jump into Roles
- ZopNight & ZopDay: removed the redundant manual Sync buttons now that discovery is fully automatic (a Refresh control remains on the Resources page)
