Roles
Karyam uses Role-Based Access Control (RBAC) to assign permissions based on a user’s responsibilities. Each role is designed to provide the appropriate level of access while maintaining security and governance across the platform.
Built-in Roles
Section titled “Built-in Roles”Karyam includes three primary roles.
| Role | Purpose |
|---|---|
| Admin | Manage the platform, users, permissions, infrastructure, and governance. |
| Developer | Build, configure, and maintain AI solutions and platform resources. |
| User | Consume published AI capabilities through the Service Catalog. |
Administrators have the highest level of access within Karyam.
Typical responsibilities include:
- Manage workspaces
- Manage users and teams
- Configure permissions
- Manage AI models and providers
- Configure Knowledge Bases and Vector Databases
- Manage Skills and MCP Servers
- Publish AI services
- Monitor platform activity
Administrators are responsible for ensuring the platform remains secure, compliant, and operational.
Developer
Section titled “Developer”Developers build and maintain AI solutions within the platform.
Typical responsibilities include:
- Create AI Agents
- Build AI Flows
- Configure Skills
- Connect MCP Servers
- Manage Knowledge Bases
- Configure Vector Databases
- Test and improve AI workflows
- Publish approved Agents and AI Flows
Developers focus on creating AI capabilities while working within the governance policies defined by administrators.
Users consume AI capabilities that have been published through the Service Catalog.
Typical responsibilities include:
- Execute published AI Flows
- Interact with published AI Agents
- Submit requests
- View personal activity
- Respond to approval requests assigned to them
Users do not have access to development or platform administration features.
Role Comparison
Section titled “Role Comparison”| Capability | Admin | Developer | User |
|---|---|---|---|
| Manage Users & Teams | ✅ | ❌ | ❌ |
| Configure Permissions | ✅ | ❌ | ❌ |
| Create AI Agents | ✅ | ✅ | ❌ |
| Create AI Flows | ✅ | ✅ | ❌ |
| Manage Knowledge Bases | ✅ | ✅ | ❌ |
| Configure Models | ✅ | ✅ | ❌ |
| Configure Skills | ✅ | ✅ | ❌ |
| Configure MCP Servers | ✅ | ✅ | ❌ |
| Publish Services | ✅ | ✅ | ❌ |
| Use Service Catalog | ✅ | ✅ | ✅ |
| Execute Published Services | ✅ | ✅ | ✅ |
Choosing the Right Role
Section titled “Choosing the Right Role”Assign roles based on the principle of least privilege.
- Admins should be limited to platform owners and administrators.
- Developers should have access only to the resources required to build and maintain AI solutions.
- Users should access AI capabilities exclusively through the Service Catalog.
