Permissions Overview
Karyam uses Role-Based Access Control (RBAC) to ensure users have access only to the resources and capabilities required for their responsibilities.
Permissions are designed to help organizations securely manage AI development, operations, and consumption while maintaining clear separation between administrators, developers, and business users.
Why Permissions Matter
Section titled “Why Permissions Matter”As organizations scale their AI initiatives, not every user should have access to every resource.
Permissions help you:
- Control access to platform resources
- Protect sensitive configurations and data
- Govern who can create, modify, or publish AI capabilities
- Enable secure collaboration across teams
- Reduce operational and security risks
Permission Model
Section titled “Permission Model”Karyam permissions are applied across different levels of the platform.
Workspace ├── Teams ├── Users └── Resources ├── Agents ├── AI Flows ├── Knowledge Bases ├── Models ├── Skills ├── MCP Servers └── Service CatalogsAccess to these resources is determined by a user’s assigned role and team membership.
Core Concepts
Section titled “Core Concepts”The permission model is built around several key concepts:
Roles define what actions a user can perform within the platform.
Typical responsibilities include:
- Platform administration
- AI development
- Business consumption of published AI services
Learn more in the Roles guide.
Resource Permissions
Section titled “Resource Permissions”Each resource has its own set of permissions that determine who can view, create, edit, delete, execute, or publish it.
Examples include:
- Agents
- AI Flows
- Knowledge Bases
- Models
- Skills
- MCP Servers
- Service Catalogs
Team Access
Section titled “Team Access”Teams simplify permission management by allowing administrators to assign access to groups of users instead of managing permissions individually.
This makes collaboration easier while ensuring consistent access across projects.
Publishing Permissions
Section titled “Publishing Permissions”Only authorized users can publish Agents and AI Flows to the Service Catalog.
Publishing makes approved AI capabilities available to business users while keeping development resources private.
Best Practices
Section titled “Best Practices”To maintain a secure and well-governed environment, consider the following recommendations:
- Assign users the minimum permissions required for their role.
- Use Teams to manage access at scale.
- Restrict publishing to trusted users.
- Separate development and production workspaces.
- Periodically review user access and published resources.
- Require Human Confirmation for sensitive or irreversible workflows.
