KAGEOS GUIDES

Users & permissions

Grant access by user, organization and directory.

Choose the scope

Grant permissions to individual users or departments. Department grants cover members of descendant departments; directory grants inherit down resource paths.

A grant on /sales can affect its customer, order and reporting directories. Prefer a narrower directory when that is sufficient.

Roles and the AI workbench

Directories use fixed roles including Viewer, Member, Admin and Owner. Each operation still checks the required read, write, update, delete or administrative permission.

Viewer cannot enter the AI workbench. Member, Admin and Owner can enter, but agents do not gain extra permissions by running there.

Public workspace visibility

A public workspace can be discoverable to signed-in users without exposing all its contents. Resource permissions continue to govern data and operations. Unauthorized nodes may appear locked or be hidden.

The current model has allow rules, not deny rules. Removing one direct grant may leave access inherited from a parent directory or department.

Troubleshoot access

  1. Confirm the signed-in account and department.
  2. Identify the workspace and full resource path.
  3. Check direct grants, parent-directory grants and department inheritance.
  4. Distinguish seeing a node from reading its data or performing an action.

Only system manages organization structure and membership. Separate enterprises should use separate deployments.