Skip to content
Karyam

Resource Permissions

Resource permissions determine who can view, create, modify, publish, and execute resources within Karyam.

Permissions help ensure that users have access only to the resources required for their responsibilities while protecting sensitive configurations and production environments.

Permissions are applied to the following resource types:

  • AI Agents
  • AI Flows
  • Knowledge Bases
  • Models
  • Skills
  • MCP Servers
  • Vector Databases
  • Service Catalogs

Depending on the resource, users may be granted one or more of the following permissions.

Permission Description
View View resource details and configuration.
Create Create new resources.
Edit Modify an existing resource.
Delete Remove a resource.
Publish Make a resource available through the Service Catalog.
Execute Run an Agent or AI Flow.

Not every resource supports every permission. For example, only publishable resources expose the Publish permission.

The following table provides a general overview of resource access by role.

Resource Admin Developer User
AI Agents Full Access Create & Manage Execute Published
AI Flows Full Access Create & Manage Execute Published
Knowledge Bases Full Access Create & Manage —
Models Full Access Create & Manage —
Skills Full Access Configure —
MCP Servers Full Access Configure —
Vector Databases Full Access Configure —
Service Catalog Manage Publish Consume

Resources remain private until they are published.

  • Visible only to authorized administrators and developers.
  • Used for development, testing, and validation.
  • Not accessible through the Service Catalog.
  • Available through the Service Catalog.
  • Can be executed by users with the appropriate permissions.
  • Continue to be managed by administrators and developers.

This separation allows teams to safely develop and test AI capabilities before making them available to business users.

Resources are managed within a workspace and are accessible only to users who have permission to that workspace.

Ownership ensures that:

  • Resources remain isolated between workspaces.
  • Teams collaborate within their assigned environments.
  • Administrative boundaries are maintained.

To keep resources secure and manageable:

  • Grant only the permissions users require.
  • Keep development and production resources separate.
  • Publish only validated Agents and AI Flows.
  • Regularly review resource ownership and access.
  • Remove unused or obsolete resources.
  • Use Human Confirmation for workflows that perform sensitive or irreversible actions.