Skip to main content

AIOS Workspace

Security

Enterprise Administration

AIOS Enterprise Security, RBAC & Multi-Tenancy

Secure multi-organization, multi-workspace AIOS deployment architecture with tenant isolation, workspace segmentation, role-based permissions, auditability, policy controls, API key governance, and session management.

Supabase Authentication linkedRuntime + Memory linkedKnowledge + Decisions + Governance linked

Organizations

2

Tenant-level enterprise isolation architecture.

Users

6

Role, department, agent, and workflow assignments.

Security mode

Monitoring

Selected scope

Northwind Health

Executive Workspace

Enterprise Governance Layer

Organizations, workspaces, users, teams, roles, permissions, audit, sessions

Everything is structured for enterprise tenancy, secure isolation, governed workflow execution, and future SSO, SAML, SCIM, Entra ID, Okta, Google Workspace, and ABAC expansion.

Enterprise readyMulti-tenantWorkspace isolatedRBAC governed
5 teams in filtered scope
Authentication

Signed-in identity

User

No identity

No email

Auth method

email

Status

Signed out

Tenant

Tenant hierarchy and settings

Selected organization

Northwind Health

production

Workspace

Executive Workspace

Domains

northwind-health.aios.example

5 workspaces governed under the current tenant.

Users

Profiles, departments, roles, and assignments

Ava Chen

ava@northwind.ai

active

Department

executive

Role

role-owner

Last login

4 min ago

Agents

2

Workflows: Quarterly Board Pack, Executive Outreach

Nina Park

nina@northwind.ai

active

Department

support

Role

role-manager

Last login

19 min ago

Agents

1

Workflows: Support Recovery Workflow

Marco Silva

marco@northwind.ai

active

Department

finance

Role

role-admin

Last login

1 hr ago

Agents

1

Workflows: Finance Approval Flow

Lena Ortiz

lena@helios.ai

invited

Department

operations

Role

role-operator

Last login

Pending invite

Agents

1

Workflows: Operational Readiness

Jon Mercer

jon@northwind.ai

active

Department

sales

Role

role-executive

Last login

14 min ago

Agents

1

Workflows: Forecast Cadence

Board Report Service

board-service@northwind.ai

active

Department

executive

Role

role-service-account

Last login

service

Agents

1

Workflows: Board Export

Teams

Department and team ownership

Executive Leadership

Lead: Ava Chen

8 members

Workspace ws-1 · Department dep-1

Revenue Ops

Lead: Jon Mercer

14 members

Workspace ws-2 · Department dep-2

Support Control

Lead: Nina Park

12 members

Workspace ws-3 · Department dep-4

Finance Governance

Lead: Marco Silva

7 members

Workspace ws-4 · Department dep-3

Operations Cell

Lead: Lena Ortiz

6 members

Workspace ws-5 · Department dep-5

Roles

Enterprise RBAC role model

Owner

organization

24 perms

Full organization authority across tenancy, security, and billing.

Administrator

organization

22 perms

Enterprise administration for users, workspaces, integrations, and policies.

Executive

workspace

7 perms

Strategic decisions, executive summaries, and risk oversight.

Manager

department

14 perms

Department leadership with execution and team oversight.

Operator

team

7 perms

Runs approved workflows and operational queues.

Employee

team

3 perms

Standard workspace access for assigned workflows and insights.

Guest

workspace

2 perms

Limited read-only visibility into shared dashboards.

Service Account

workspace

6 perms

Non-human automation identity with scoped API access.

Permissions

Granular enterprise permission architecture

view_dashboard

dashboard

7 roles

View executive and operational dashboards.

Assigned roles: Owner, Administrator, Executive, Manager, Operator, Employee, Guest

manage_agents

agents

4 roles

Create and operate autonomous agent execution.

Assigned roles: Owner, Administrator, Manager, Operator

manage_memory

memory

5 roles

Manage enterprise memory and retention controls.

Assigned roles: Owner, Administrator, Manager, Operator, Service Account

manage_users

users

3 roles

Invite users and assign access scope.

Assigned roles: Owner, Administrator, Manager

manage_roles

roles

2 roles

Manage role definitions and assignments.

Assigned roles: Owner, Administrator

manage_workflows

workflows

5 roles

Create and schedule enterprise workflows.

Assigned roles: Owner, Administrator, Manager, Operator, Service Account

manage_integrations

integrations

3 roles

Connect and govern platform integrations.

Assigned roles: Owner, Administrator, Service Account

view_audit_logs

audit

4 roles

Read audit events and security evidence.

Assigned roles: Owner, Administrator, Executive, Manager

manage_api_keys

api-keys

3 roles

Issue, rotate, and revoke API keys.

Assigned roles: Owner, Administrator, Service Account

export_data

export

4 roles

Export governed tenant data.

Assigned roles: Owner, Administrator, Executive, Manager

manage_policies

policy

2 roles

Update security and compliance policies.

Assigned roles: Owner, Administrator

manage_sessions

sessions

3 roles

Revoke and manage active sessions.

Assigned roles: Owner, Administrator, Manager

manage_departments

departments

3 roles

Manage department structure and ownership.

Assigned roles: Owner, Administrator, Manager

manage_teams

teams

3 roles

Manage team structures and membership.

Assigned roles: Owner, Administrator, Manager

manage_organizations

organizations

1 roles

Govern organization-level settings and controls.

Assigned roles: Owner

manage_workspaces

workspaces

2 roles

Create and configure workspace boundaries.

Assigned roles: Owner, Administrator

view_runtime

runtime

7 roles

View runtime status and system health.

Assigned roles: Owner, Administrator, Executive, Manager, Operator, Employee, Service Account

manage_runtime

runtime

2 roles

Control runtime execution settings.

Assigned roles: Owner, Administrator

approve_decisions

decisions

4 roles

Approve strategic recommendations.

Assigned roles: Owner, Administrator, Executive, Manager

view_reports

reports

6 roles

View reports and briefings.

Assigned roles: Owner, Administrator, Executive, Manager, Employee, Guest

manage_knowledge

knowledge

4 roles

Manage knowledge graph context and updates.

Assigned roles: Owner, Administrator, Executive, Manager

manage_billing

billing

1 roles

Manage subscriptions and billing controls.

Assigned roles: Owner

manage_ai_models

models

2 roles

Govern model access and policy alignment.

Assigned roles: Owner, Administrator

execute_workflow

workflows

5 roles

Execute approved automation workflows.

Assigned roles: Owner, Administrator, Manager, Operator, Service Account

Security Policies

Password, MFA, session, network, and retention controls

Password Policy

password

active

Require strong passwords and periodic rotation for enterprise admins.

14 chars / 90 days

MFA

mfa

active

MFA required for privileged roles and decision approvals.

Required for Owner/Admin/Executive

Session Timeout

session-timeout

review

Shorter session duration for high-risk workspaces.

30 minutes idle

IP Restrictions

ip-restrictions

draft

Geo-aware restrictions for regulated tenants.

Allow-list ready

Device Trust

device-trust

active

Trusted devices flagged for executive and finance workspaces.

Managed devices preferred

Data Retention

data-retention

active

Retention architecture for audit, memory, and workflow evidence.

365 days default

Enterprise SSO

sso

draft

SSO foundation prepared for Entra ID, Okta, and Google Workspace.

OIDC/SAML staged

SCIM Provisioning

scim

draft

SCIM user lifecycle sync contracts staged for enterprise rollout.

Endpoint pending

Realtime idleUpdated 0s ago5 active modules4 agents · 3 pending

Revenue forecast dropped 12%

ERROR

Q3 forecast variance exceeded threshold across two enterprise regions.

AI_DECISION · CRITICAL

Impact 96% · Confidence 94%