RBAC
Role-Based Access Control (RBAC) is the authorization model used by Karyam to control access to platform capabilities and resources.
Rather than assigning permissions individually to every user, Karyam grants access through predefined roles.
This simplifies administration while ensuring users only have access to the functionality required for their responsibilities.
Why RBAC Exists
Section titled “Why RBAC Exists”Not every user in an organization should have access to:
- AI Infrastructure
- Models
- Vector Databases
- MCP Servers
- Governance Settings
- Production AI Systems
RBAC ensures users only see and interact with the parts of the platform relevant to their role.
This reduces operational risk and improves governance.
Karyam Roles
Section titled “Karyam Roles”Karyam currently supports three primary roles.
| Role | Purpose |
|---|---|
| Admin | Manage platform configuration, governance, and infrastructure |
| Developer | Build and operate AI systems |
| User | Consume published AI capabilities |
Administrators have full access to the workspace.
Typical responsibilities include:
- Managing users and teams
- Configuring AI infrastructure
- Managing approvals
- Reviewing audit logs
- Publishing services
- Managing governance policies
Admins are responsible for operating and governing the platform.
Developer
Section titled “Developer”Developers build and maintain AI systems.
Typical responsibilities include:
- Creating Agents
- Building AI Flows
- Configuring Skills
- Managing Models
- Creating MCP Server connections
- Managing Listeners
- Configuring Vector Databases
Developers focus on building AI capabilities.
Users consume published AI services through the Service Catalog.
Typical responsibilities include:
- Running published Agents
- Executing AI Flows
- Viewing personal runs
- Responding to approvals assigned to them
Users do not interact directly with platform infrastructure.
RBAC and Service Catalogs
Section titled “RBAC and Service Catalogs”Service Catalogs are the primary interface for users.
This allows organizations to expose AI capabilities without exposing implementation details.
For example:
Developer ↓Builds VPN Assistant
Admin ↓Publishes VPN Assistant
User ↓Uses VPN AssistantRBAC and Teams
Section titled “RBAC and Teams”RBAC works alongside Teams.
Users ↓Teams ↓Roles ↓PermissionsTeams provide organizational grouping.
Roles determine what those groups can access.
RBAC and Workspaces
Section titled “RBAC and Workspaces”Permissions are evaluated within the context of a Workspace.
This means a user may have:
Developer in Engineering Workspace
User in Finance Workspace
Admin in Sandbox WorkspaceRoles are not necessarily global across the organization.
Principle of Least Privilege
Section titled “Principle of Least Privilege”Karyam follows the principle of least privilege.
Users should only receive the minimum permissions required to perform their responsibilities.
Benefits include:
- Improved security
- Reduced operational risk
- Better governance
- Simplified compliance
Relationship to Other Concepts
Section titled “Relationship to Other Concepts”Users ↓Teams ↓RBAC ↓Workspaces ↓ResourcesRBAC sits between users and the resources they are allowed to access.
The Karyam Philosophy
Section titled “The Karyam Philosophy”AI systems often interact with sensitive business data and critical workflows.
Governance should be built into the platform rather than added later.
RBAC ensures organizations can scale AI adoption while maintaining security and control.
