Back to features

Govern

Role-based access control

Access is decided in three layers: what a role may do, which parts of the schema it may do it to, and which individual records it can see. Every layer applies on the API and in the UI alike, and an agent session inherits the whole stack from the person who authorized it.

The three layers

01

Named permissions

Each module publishes the actions it allows — create entities, delete entities, edit roles, and so on — and a role is assembled from that catalog. Whether a role may delete a record at all is settled here.

02

Resource restrictions

Point a role at one template or one attribute and set how far it reaches: deny, view, edit, or full. This is the exception layer, for when a role needs different treatment on a specific part of the schema.

03

Row-level entity scopes

Conditions on attribute values decide which individual records a role sees, using eq, neq, gt, lt, like, not-like, empty, and not-empty. A contractor role reaches the sites assigned to it and nothing else.

The four access levels

Levels are ordered full, edit, view, deny. A level satisfies any requirement at or below its own rank, with one exception: a denial satisfies nothing at all.

Deny

Satisfies nothing

A denial is absolute. It never satisfies a requirement, whatever else the role carries.

View

Read

Satisfied by any positive level. The floor for cross-functional teams and reviewers.

Edit

Read and write

Satisfied by edit or full. Enough to change values on the resource it covers.

Full

Read, write, and administer

The only level that satisfies a full requirement, and the top of the hierarchy.

Scopes apply where the query is built

A role's row-level conditions are compiled into the query that fetches the records, so the restriction holds on every read path the API serves: browsing, search, exports, and an agent session alike.

The same rules on the API

A programmatic access token is issued for the authenticated user inside the active project, and it inherits that user's role permissions and scopes. A script cannot reach past what the person who created its token can reach.

Tokens carry an omni_ prefix and a required expiry date. The secret is returned once at creation and cannot be recovered afterwards. A lost token is replaced with a new one.

Explore other capabilities

Give your agent somewhere to build.

The free tier carries 250 entities, 25 attributes, and 1,000 AI credits, with the same history, metrics, and API as every other tier. No credit card required.

Questions? [email protected]