Skip to content

Permission catalog#

Every permission there is, as resource:action. Roles are sets of these (Roles and permissions); the console's roles editor shows the same list as a checklist, and GET /iam/catalog (astra iam catalog) returns it.

  • resource:* in a role means every action of the resource.
  • ⚠ marks a dangerous action: presets grant them only where Presets says so.
  • Lives in says which scopes grant it: organisation — organisation assignments only; cluster — organisation, cluster or pool assignments; workspace — organisation, cluster, workspace or one-resource assignments.
  • ‡ Held by every member of the organisation (or, in a workspace, by everyone who reaches it): checked as membership, listed so that roles say it.
  • † In the catalog for the roles you write now, but not yet checked on its own: until it is, the action is allowed or refused by the resource's other permissions (for example notebooks:read-content by environments:connect, through which a notebook's file is read).

read-content is apart from read on purpose: metadata (names, states, sizes) is not content (logs, outputs, prompts, traces, files). A role that reads only metadata is safe for people who must not see personal data.

Organisation and people#

Resource Lives in Actions What it covers
organization organisation read ‡, update, delete ⚠, transfer-ownership ⚠ The organisation: name, settings.
members organisation read ‡, invite, update-role, remove ⚠ The organisation's people.
invitations organisation read, create †, resend †, revoke Invitations waiting to be accepted.
groups organisation read, map-to-role Groups mirrored from the identity provider.
roles organisation read, create, update, delete Roles: sets of permissions.
assignments organisation read, create, delete Who has which role where.
sso organisation read, configure ⚠ Single sign-on, SCIM tokens, domains.
people-settings organisation read ‡, update Who may invite outside guests; suggestions.
guests organisation read, invite, revoke People given one environment or notebook.
audit-log organisation read, export Who did what.
usage organisation read What was used: GPU hours, tokens, cost.
billing organisation read †, update Plan, payment, limits.
alerts organisation read, create, update, delete, test Alert rules and channels (e-mail, Slack, webhook, PagerDuty, Opsgenie).
event-streams organisation read, create, delete, test Events streamed to a SIEM or NATS.
api-tokens organisation create ‡, revoke ‡, revoke-any ⚠ † Personal API tokens (one's own; an admin may revoke anyone's).
connected-apps organisation read ‡, revoke ‡, allow-org ⚠ † AI assistants and other OAuth clients.
marketplace organisation read ‡, publish, delete The organisation's marketplace of templates.
guardrails organisation read ‡, update Organisation policies on every workspace's agents.
hosted-gateway-policy organisation read ‡, update ⚠ Whether the hosted gateway may serve the organisation.

Clusters and workspaces#

Resource Lives in Actions What it covers
clusters organisation read ‡, connect ⚠, update, delete ⚠, use-hosted The organisation's clusters.
cluster-version cluster read ‡, upgrade ⚠ † The release a cluster runs.
workspaces workspace read ‡, create, update, delete ⚠ Workspaces.
bindings workspace read, update ⚠ A workspace on a cluster: quota, weight, pools, max priority.
workspace-members workspace read, add, update-role, remove A workspace's people.
events workspace read, update-retention The activity feed and how long records are kept.
templates workspace read, publish, delete A workspace's saved run templates.
library workspace read The model library judged against the workspace's machines.

Machines, pools and health#

Resource Lives in Actions What it covers
machines cluster read, read-metrics, read-content, enroll, remove ⚠, cordon, uncordon, drain ⚠, undrain, maintenance ⚠, set-placement, set-data-location, observe-only, accept, clear-gpu-fault, upgrade-agent ⚠ Machines (read-content: a machine's own logs).
bmc cluster read, configure ⚠, power-cycle ⚠ † Machines' BMCs (never their credentials).
pools cluster read †, update, use † Pools of machines (labels); use: place work on them.
reservations cluster read, create, update, delete Windows on machines for workspaces.
topology cluster read, export, sweep The cluster's network; its Slurm export; fabric discovery.
validations cluster read, run, run-fabric-tests ⚠, cancel Checks, acceptance, the Cluster Report.
validation-policies cluster read, update Checks required per pool.
machine-health cluster read, close, escalate, rma Machines' health and incidents.
remediation-actions cluster read, approve ⚠, reject Repairs, and those waiting for a person.
remediation-policies cluster read, update ⚠ Autonomy per fault class and pool.
remediation-breakers cluster read, reset ⚠ Circuit breakers on repairs.
remediation-receipts cluster read, verify † Signed receipts of repairs.
prices cluster read The hosted cluster's and models' prices.

Runs and services#

Resource Lives in Actions What it covers
runs workspace read, read-content, create, update, cancel, restart, delete, update-priority † Runs (read-content: logs, outputs, metrics).
workers workspace read, read-content, connect ⚠, restart A run's workers (read-content: logs, live metrics; connect: shell, ports).
schedules workspace read, create, update, delete, trigger Schedules.
endpoints workspace read, create, update, delete, expose-externally ⚠, call Endpoints; call: through the proxy.
replica-groups workspace read, create, update, delete, scale Replica groups.
functions workspace read, read-content, create, update, delete, call Functions (read-content: invocations' logs).

Data#

Resource Lives in Actions What it covers
drives workspace read, read-content, create, update, delete, use, copy, evict † Drives (read-content: browse, download, diffs).
mounts workspace read, create, delete Mounts: drives claimed by runs.
data-sources workspace read, read-content, create, update, delete, use † Buckets, NFS, Hugging Face, databases (read-content: files, previews).
catalog workspace read †, read-content † Data manifests and profiles.
credentials workspace read, create, update, delete, use ⚠ Credentials (names and where they resolve, never values).
sealing workspace read, rotate ⚠ Sealed-credential keys.

Eos: inference#

Resource Lives in Actions What it covers
models workspace read, create, delete, pull Models.
deployments workspace read, read-metrics, create, update, delete, scale, call, gateway-reachable ⚠ † Deployments; call: Playground, gateway.
deployment-shares workspace read, share ⚠, revoke Deployments shared with workspaces and people.
shared-deployments workspace read, call Others' deployments shared with this workspace.
api-keys workspace read, create, update, revoke Gateway API keys.
gateway-usage workspace read † What the gateway served.
playground workspace read-content † The Playground's history (calling is deployments:call).

Anemoi: agents#

Resource Lives in Actions What it covers
agents workspace read, create, update, delete, run Agents and their versions.
agent-runs workspace read, read-content, cancel † Agent runs (read-content: traces, tool calls, prompts).
agent-templates workspace read, create, update †, delete † Agent templates, sandbox compositions.
agent-policies workspace read, update ⚠, test Cedar policies, guardrails, budgets.
approvals workspace read, read-content, approve ⚠, reject Held tool calls (read-content: what the call would do).
agent-receipts workspace read, verify † Agent runs' signed receipts.
oauth-connections workspace read, create ⚠, revoke, use † Tools' OAuth connections to third parties.
flows workspace read, create, update, delete, trigger Durable flows.
flow-executions workspace read, read-content †, cancel, retry Flow executions.
evals workspace read, read-content, create, run, delete, promote ⚠ Eval suites and runs (read-content: suites' cases); promote: the promotion gate.
evidence-packs workspace read, create, download, delete Signed evidence packs.
openshell workspace read †, use † The OpenShell sandbox driver.

Hesperus: notebooks and environments#

Resource Lives in Actions What it covers
notebooks workspace read, read-content †, create, update, delete, run, share † Notebooks (read-content: cells, outputs).
notebook-images workspace read, create, delete Notebook images.
notebook-limits workspace read, update ⚠ Limits per person.
environments workspace read, create, start, stop, delete, connect ⚠, share Environments and runtimes (connect: IDE, SSH, apps).
collab-sessions workspace join †, host †, allow-terminal ⚠ † Shared notebook, editor, terminal.
ssh-certificates workspace create, configure-ca ⚠ † SSH certificates (one's own); the workspace SSH CA.

What a request needs#

Every request to a cluster needs one permission, which the cluster checks against what the person holds there — on the object the request names, and, for a grant held to a pool, on the machine's labels. Some examples:

Request Needs
List runs, read one runs:read
A run's logs, its metrics runs:read-content
A worker's logs workers:read-content
Stop a run's worker runs:cancel
Requeue a worker runs:restart
A worker's port through Astralyx workers:connect
A run that references a credential runs:create and credentials:use
A run that mounts a drive runs:create and drives:use
A run or an endpoint exposed outside the cluster endpoints:expose-externally
An environment's IDE, SSH or apps environments:connect
One agent run (its trace) / the list of runs agent-runs:read-content / agent-runs:read
A held call's arguments / deciding it approvals:read-content / approvals:approve or approvals:reject
Promoting an agent past its gate evals:promote
A machine's own logs (journald, kernel) machines:read-content
Draining a machine machines:drain

A refusal is 403 PERMISSION_DENIED, naming the permission in detail.permission.