Zum Inhalt springen

Roles and permissions (RBAC)

Dieser Inhalt ist noch nicht in deiner Sprache verfügbar.

RoleTypical personHighlights
adminplatform ownerall permissions
agent-engineerbuilds agentswrite and publish agents, run and cancel runs, manage own API tokens
integratorconnects systemsmanage event sources and connections, read policies
operatorruns the servicerun, cancel and approve runs
auditorcompliance, securityread, verify and export the audit trail; read policies, connections, users, settings
viewereveryone elseread agents, runs, events and costs

agents:read|write|publish, runs:read|execute|cancel|approve, events:read, sources:read|write, connections:read|write, policies:read|write, audit:read|verify|export, costs:read, users:read|write, tokens:read|write, settings:read|write.

Nobody can change or delete audit entries; the audit trail is append-only by design.

A role binding is { role, teamId }. teamId: null grants the role globally; otherwise it applies to the team’s agents, runs and connections. API tokens for machines can carry scopes that narrow their permissions further. Tenants and per-agent bindings are described in Tenants and per-agent access.

Available in 0.1 OIDC (Keycloak, Entra ID, Okta and others), LDAP/AD bind with group-to-role mapping, a local admin bootstrap account and hashed, scoped, expiring API tokens. Every API route declares the permission it needs, and tests enforce it.