Permission catalog
Every permission there is, as resource:action. Roles are sets of these
(Roles and permissions); the console's roles editor shows the same
list as a checklist, and GET /iam/catalog (astra iam catalog) returns it.
resource:* in a role means every action of the resource.
- ⚠ marks a dangerous action: presets grant them only where
Presets says so.
- Lives in says which scopes grant it: organisation — organisation
assignments only; cluster — organisation, cluster or pool assignments;
workspace — organisation, cluster, workspace or one-resource
assignments.
- ‡ Held by every member of the organisation (or, in a workspace, by
everyone who reaches it): checked as membership, listed so that roles say
it.
- † In the catalog for the roles you write now, but not yet checked on its
own: until it is, the action is allowed or refused by the resource's other
permissions (for example
notebooks:read-content by
environments:connect, through which a notebook's file is read).
read-content is apart from read on purpose: metadata (names, states,
sizes) is not content (logs, outputs, prompts, traces, files). A role that
reads only metadata is safe for people who must not see personal data.
Organisation and people
| Resource |
Lives in |
Actions |
What it covers |
organization |
organisation |
read ‡, update, delete ⚠, transfer-ownership ⚠ |
The organisation: name, settings. |
members |
organisation |
read ‡, invite, update-role, remove ⚠ |
The organisation's people. |
invitations |
organisation |
read, create †, resend †, revoke |
Invitations waiting to be accepted. |
groups |
organisation |
read, map-to-role |
Groups mirrored from the identity provider. |
roles |
organisation |
read, create, update, delete |
Roles: sets of permissions. |
assignments |
organisation |
read, create, delete |
Who has which role where. |
sso |
organisation |
read, configure ⚠ |
Single sign-on, SCIM tokens, domains. |
people-settings |
organisation |
read ‡, update |
Who may invite outside guests; suggestions. |
guests |
organisation |
read, invite, revoke |
People given one environment or notebook. |
audit-log |
organisation |
read, export |
Who did what. |
usage |
organisation |
read |
What was used: GPU hours, tokens, cost. |
billing |
organisation |
read †, update |
Plan, payment, limits. |
alerts |
organisation |
read, create, update, delete, test |
Alert rules and channels (e-mail, Slack, webhook, PagerDuty, Opsgenie). |
event-streams |
organisation |
read, create, delete, test |
Events streamed to a SIEM or NATS. |
api-tokens |
organisation |
create ‡, revoke ‡, revoke-any ⚠ † |
Personal API tokens (one's own; an admin may revoke anyone's). |
connected-apps |
organisation |
read ‡, revoke ‡, allow-org ⚠ † |
AI assistants and other OAuth clients. |
marketplace |
organisation |
read ‡, publish, delete |
The organisation's marketplace of templates. |
guardrails |
organisation |
read ‡, update |
Organisation policies on every workspace's agents. |
hosted-gateway-policy |
organisation |
read ‡, update ⚠ |
Whether the hosted gateway may serve the organisation. |
Clusters and workspaces
| Resource |
Lives in |
Actions |
What it covers |
clusters |
organisation |
read ‡, connect ⚠, update, delete ⚠, use-hosted |
The organisation's clusters. |
cluster-version |
cluster |
read ‡, upgrade ⚠ † |
The release a cluster runs. |
workspaces |
workspace |
read ‡, create, update, delete ⚠ |
Workspaces. |
bindings |
workspace |
read, update ⚠ |
A workspace on a cluster: quota, weight, pools, max priority. |
workspace-members |
workspace |
read, add, update-role, remove |
A workspace's people. |
events |
workspace |
read, update-retention |
The activity feed and how long records are kept. |
templates |
workspace |
read, publish, delete |
A workspace's saved run templates. |
library |
workspace |
read |
The model library judged against the workspace's machines. |
Machines, pools and health
| Resource |
Lives in |
Actions |
What it covers |
machines |
cluster |
read, read-metrics, read-content, enroll, remove ⚠, cordon, uncordon, drain ⚠, undrain, maintenance ⚠, set-placement, set-data-location, observe-only, accept, clear-gpu-fault, upgrade-agent ⚠ |
Machines (read-content: a machine's own logs). |
bmc |
cluster |
read, configure ⚠, power-cycle ⚠ † |
Machines' BMCs (never their credentials). |
pools |
cluster |
read †, update, use † |
Pools of machines (labels); use: place work on them. |
reservations |
cluster |
read, create, update, delete |
Windows on machines for workspaces. |
topology |
cluster |
read, export, sweep |
The cluster's network; its Slurm export; fabric discovery. |
validations |
cluster |
read, run, run-fabric-tests ⚠, cancel |
Checks, acceptance, the Cluster Report. |
validation-policies |
cluster |
read, update |
Checks required per pool. |
machine-health |
cluster |
read, close, escalate, rma |
Machines' health and incidents. |
remediation-actions |
cluster |
read, approve ⚠, reject |
Repairs, and those waiting for a person. |
remediation-policies |
cluster |
read, update ⚠ |
Autonomy per fault class and pool. |
remediation-breakers |
cluster |
read, reset ⚠ |
Circuit breakers on repairs. |
remediation-receipts |
cluster |
read, verify † |
Signed receipts of repairs. |
prices |
cluster |
read |
The hosted cluster's and models' prices. |
Runs and services
| Resource |
Lives in |
Actions |
What it covers |
runs |
workspace |
read, read-content, create, update, cancel, restart, delete, update-priority † |
Runs (read-content: logs, outputs, metrics). |
workers |
workspace |
read, read-content, connect ⚠, restart |
A run's workers (read-content: logs, live metrics; connect: shell, ports). |
schedules |
workspace |
read, create, update, delete, trigger |
Schedules. |
endpoints |
workspace |
read, create, update, delete, expose-externally ⚠, call |
Endpoints; call: through the proxy. |
replica-groups |
workspace |
read, create, update, delete, scale |
Replica groups. |
functions |
workspace |
read, read-content, create, update, delete, call |
Functions (read-content: invocations' logs). |
Data
| Resource |
Lives in |
Actions |
What it covers |
drives |
workspace |
read, read-content, create, update, delete, use, copy, evict † |
Drives (read-content: browse, download, diffs). |
mounts |
workspace |
read, create, delete |
Mounts: drives claimed by runs. |
data-sources |
workspace |
read, read-content, create, update, delete, use † |
Buckets, NFS, Hugging Face, databases (read-content: files, previews). |
catalog |
workspace |
read †, read-content † |
Data manifests and profiles. |
credentials |
workspace |
read, create, update, delete, use ⚠ |
Credentials (names and where they resolve, never values). |
sealing |
workspace |
read, rotate ⚠ |
Sealed-credential keys. |
Eos: inference
| Resource |
Lives in |
Actions |
What it covers |
models |
workspace |
read, create, delete, pull |
Models. |
deployments |
workspace |
read, read-metrics, create, update, delete, scale, call, gateway-reachable ⚠ † |
Deployments; call: Playground, gateway. |
deployment-shares |
workspace |
read, share ⚠, revoke |
Deployments shared with workspaces and people. |
shared-deployments |
workspace |
read, call |
Others' deployments shared with this workspace. |
api-keys |
workspace |
read, create, update, revoke |
Gateway API keys. |
gateway-usage |
workspace |
read † |
What the gateway served. |
playground |
workspace |
read-content † |
The Playground's history (calling is deployments:call). |
Anemoi: agents
| Resource |
Lives in |
Actions |
What it covers |
agents |
workspace |
read, create, update, delete, run |
Agents and their versions. |
agent-runs |
workspace |
read, read-content, cancel † |
Agent runs (read-content: traces, tool calls, prompts). |
agent-templates |
workspace |
read, create, update †, delete † |
Agent templates, sandbox compositions. |
agent-policies |
workspace |
read, update ⚠, test |
Cedar policies, guardrails, budgets. |
approvals |
workspace |
read, read-content, approve ⚠, reject |
Held tool calls (read-content: what the call would do). |
agent-receipts |
workspace |
read, verify † |
Agent runs' signed receipts. |
oauth-connections |
workspace |
read, create ⚠, revoke, use † |
Tools' OAuth connections to third parties. |
flows |
workspace |
read, create, update, delete, trigger |
Durable flows. |
flow-executions |
workspace |
read, read-content †, cancel, retry |
Flow executions. |
evals |
workspace |
read, read-content, create, run, delete, promote ⚠ |
Eval suites and runs (read-content: suites' cases); promote: the promotion gate. |
evidence-packs |
workspace |
read, create, download, delete |
Signed evidence packs. |
openshell |
workspace |
read †, use † |
The OpenShell sandbox driver. |
Hesperus: notebooks and environments
| Resource |
Lives in |
Actions |
What it covers |
notebooks |
workspace |
read, read-content †, create, update, delete, run, share † |
Notebooks (read-content: cells, outputs). |
notebook-images |
workspace |
read, create, delete |
Notebook images. |
notebook-limits |
workspace |
read, update ⚠ |
Limits per person. |
environments |
workspace |
read, create, start, stop, delete, connect ⚠, share |
Environments and runtimes (connect: IDE, SSH, apps). |
collab-sessions |
workspace |
join †, host †, allow-terminal ⚠ † |
Shared notebook, editor, terminal. |
ssh-certificates |
workspace |
create, configure-ca ⚠ † |
SSH certificates (one's own); the workspace SSH CA. |
What a request needs
Every request to a cluster needs one permission, which the cluster checks
against what the person holds there — on the object the request names, and,
for a grant held to a pool, on the machine's labels. Some examples:
| Request |
Needs |
| List runs, read one |
runs:read |
| A run's logs, its metrics |
runs:read-content |
| A worker's logs |
workers:read-content |
| Stop a run's worker |
runs:cancel |
| Requeue a worker |
runs:restart |
| A worker's port through Astralyx |
workers:connect |
| A run that references a credential |
runs:create and credentials:use |
| A run that mounts a drive |
runs:create and drives:use |
| A run or an endpoint exposed outside the cluster |
endpoints:expose-externally |
| An environment's IDE, SSH or apps |
environments:connect |
| One agent run (its trace) / the list of runs |
agent-runs:read-content / agent-runs:read |
| A held call's arguments / deciding it |
approvals:read-content / approvals:approve or approvals:reject |
| Promoting an agent past its gate |
evals:promote |
| A machine's own logs (journald, kernel) |
machines:read-content |
| Draining a machine |
machines:drain |
A refusal is 403 PERMISSION_DENIED, naming the permission in
detail.permission.