Resource Permissions
Resource permissions determine who can view, create, modify, publish, and execute resources within Karyam.
Permissions help ensure that users have access only to the resources required for their responsibilities while protecting sensitive configurations and production environments.
Resource Types
Section titled “Resource Types”Permissions are applied to the following resource types:
- AI Agents
- AI Flows
- Knowledge Bases
- Models
- Skills
- MCP Servers
- Vector Databases
- Service Catalogs
Permission Levels
Section titled “Permission Levels”Depending on the resource, users may be granted one or more of the following permissions.
| Permission | Description |
|---|---|
| View | View resource details and configuration. |
| Create | Create new resources. |
| Edit | Modify an existing resource. |
| Delete | Remove a resource. |
| Publish | Make a resource available through the Service Catalog. |
| Execute | Run an Agent or AI Flow. |
Not every resource supports every permission. For example, only publishable resources expose the Publish permission.
Resource Access
Section titled “Resource Access”The following table provides a general overview of resource access by role.
| Resource | Admin | Developer | User |
|---|---|---|---|
| AI Agents | Full Access | Create & Manage | Execute Published |
| AI Flows | Full Access | Create & Manage | Execute Published |
| Knowledge Bases | Full Access | Create & Manage | — |
| Models | Full Access | Create & Manage | — |
| Skills | Full Access | Configure | — |
| MCP Servers | Full Access | Configure | — |
| Vector Databases | Full Access | Configure | — |
| Service Catalog | Manage | Publish | Consume |
Published vs Unpublished Resources
Section titled “Published vs Unpublished Resources”Resources remain private until they are published.
Unpublished
Section titled “Unpublished”- Visible only to authorized administrators and developers.
- Used for development, testing, and validation.
- Not accessible through the Service Catalog.
Published
Section titled “Published”- Available through the Service Catalog.
- Can be executed by users with the appropriate permissions.
- Continue to be managed by administrators and developers.
This separation allows teams to safely develop and test AI capabilities before making them available to business users.
Resource Ownership
Section titled “Resource Ownership”Resources are managed within a workspace and are accessible only to users who have permission to that workspace.
Ownership ensures that:
- Resources remain isolated between workspaces.
- Teams collaborate within their assigned environments.
- Administrative boundaries are maintained.
Best Practices
Section titled “Best Practices”To keep resources secure and manageable:
- Grant only the permissions users require.
- Keep development and production resources separate.
- Publish only validated Agents and AI Flows.
- Regularly review resource ownership and access.
- Remove unused or obsolete resources.
- Use Human Confirmation for workflows that perform sensitive or irreversible actions.
