Organizations
2
Tenant-level enterprise isolation architecture.
AIOS Workspace
Security
Enterprise Administration
Secure multi-organization, multi-workspace AIOS deployment architecture with tenant isolation, workspace segmentation, role-based permissions, auditability, policy controls, API key governance, and session management.
Organizations
2
Tenant-level enterprise isolation architecture.
Users
6
Role, department, agent, and workflow assignments.
Security mode
Selected scope
Northwind Health
Executive Workspace
Enterprise Governance Layer
Everything is structured for enterprise tenancy, secure isolation, governed workflow execution, and future SSO, SAML, SCIM, Entra ID, Okta, Google Workspace, and ABAC expansion.
User
No identity
No email
Auth method
Status
Signed out
Selected organization
Northwind Health
production
Workspace
Executive Workspace
Domains
northwind-health.aios.example
5 workspaces governed under the current tenant.
Users
Ava Chen
ava@northwind.ai
Department
executive
Role
role-owner
Last login
4 min ago
Agents
2
Workflows: Quarterly Board Pack, Executive Outreach
Nina Park
nina@northwind.ai
Department
support
Role
role-manager
Last login
19 min ago
Agents
1
Workflows: Support Recovery Workflow
Marco Silva
marco@northwind.ai
Department
finance
Role
role-admin
Last login
1 hr ago
Agents
1
Workflows: Finance Approval Flow
Lena Ortiz
lena@helios.ai
Department
operations
Role
role-operator
Last login
Pending invite
Agents
1
Workflows: Operational Readiness
Jon Mercer
jon@northwind.ai
Department
sales
Role
role-executive
Last login
14 min ago
Agents
1
Workflows: Forecast Cadence
Board Report Service
board-service@northwind.ai
Department
executive
Role
role-service-account
Last login
service
Agents
1
Workflows: Board Export
Teams
Executive Leadership
Lead: Ava Chen
Workspace ws-1 · Department dep-1
Revenue Ops
Lead: Jon Mercer
Workspace ws-2 · Department dep-2
Support Control
Lead: Nina Park
Workspace ws-3 · Department dep-4
Finance Governance
Lead: Marco Silva
Workspace ws-4 · Department dep-3
Operations Cell
Lead: Lena Ortiz
Workspace ws-5 · Department dep-5
Roles
Owner
organization
Full organization authority across tenancy, security, and billing.
Administrator
organization
Enterprise administration for users, workspaces, integrations, and policies.
Executive
workspace
Strategic decisions, executive summaries, and risk oversight.
Manager
department
Department leadership with execution and team oversight.
Operator
team
Runs approved workflows and operational queues.
Employee
team
Standard workspace access for assigned workflows and insights.
Guest
workspace
Limited read-only visibility into shared dashboards.
Service Account
workspace
Non-human automation identity with scoped API access.
Permissions
view_dashboard
dashboard
View executive and operational dashboards.
Assigned roles: Owner, Administrator, Executive, Manager, Operator, Employee, Guest
manage_agents
agents
Create and operate autonomous agent execution.
Assigned roles: Owner, Administrator, Manager, Operator
manage_memory
memory
Manage enterprise memory and retention controls.
Assigned roles: Owner, Administrator, Manager, Operator, Service Account
manage_users
users
Invite users and assign access scope.
Assigned roles: Owner, Administrator, Manager
manage_roles
roles
Manage role definitions and assignments.
Assigned roles: Owner, Administrator
manage_workflows
workflows
Create and schedule enterprise workflows.
Assigned roles: Owner, Administrator, Manager, Operator, Service Account
manage_integrations
integrations
Connect and govern platform integrations.
Assigned roles: Owner, Administrator, Service Account
view_audit_logs
audit
Read audit events and security evidence.
Assigned roles: Owner, Administrator, Executive, Manager
manage_api_keys
api-keys
Issue, rotate, and revoke API keys.
Assigned roles: Owner, Administrator, Service Account
export_data
export
Export governed tenant data.
Assigned roles: Owner, Administrator, Executive, Manager
manage_policies
policy
Update security and compliance policies.
Assigned roles: Owner, Administrator
manage_sessions
sessions
Revoke and manage active sessions.
Assigned roles: Owner, Administrator, Manager
manage_departments
departments
Manage department structure and ownership.
Assigned roles: Owner, Administrator, Manager
manage_teams
teams
Manage team structures and membership.
Assigned roles: Owner, Administrator, Manager
manage_organizations
organizations
Govern organization-level settings and controls.
Assigned roles: Owner
manage_workspaces
workspaces
Create and configure workspace boundaries.
Assigned roles: Owner, Administrator
view_runtime
runtime
View runtime status and system health.
Assigned roles: Owner, Administrator, Executive, Manager, Operator, Employee, Service Account
manage_runtime
runtime
Control runtime execution settings.
Assigned roles: Owner, Administrator
approve_decisions
decisions
Approve strategic recommendations.
Assigned roles: Owner, Administrator, Executive, Manager
view_reports
reports
View reports and briefings.
Assigned roles: Owner, Administrator, Executive, Manager, Employee, Guest
manage_knowledge
knowledge
Manage knowledge graph context and updates.
Assigned roles: Owner, Administrator, Executive, Manager
manage_billing
billing
Manage subscriptions and billing controls.
Assigned roles: Owner
manage_ai_models
models
Govern model access and policy alignment.
Assigned roles: Owner, Administrator
execute_workflow
workflows
Execute approved automation workflows.
Assigned roles: Owner, Administrator, Manager, Operator, Service Account
Security Policies
Password Policy
password
Require strong passwords and periodic rotation for enterprise admins.
14 chars / 90 days
MFA
mfa
MFA required for privileged roles and decision approvals.
Required for Owner/Admin/Executive
Session Timeout
session-timeout
Shorter session duration for high-risk workspaces.
30 minutes idle
IP Restrictions
ip-restrictions
Geo-aware restrictions for regulated tenants.
Allow-list ready
Device Trust
device-trust
Trusted devices flagged for executive and finance workspaces.
Managed devices preferred
Data Retention
data-retention
Retention architecture for audit, memory, and workflow evidence.
365 days default
Enterprise SSO
sso
SSO foundation prepared for Entra ID, Okta, and Google Workspace.
OIDC/SAML staged
SCIM Provisioning
scim
SCIM user lifecycle sync contracts staged for enterprise rollout.
Endpoint pending
Revenue forecast dropped 12%
ERRORQ3 forecast variance exceeded threshold across two enterprise regions.
AI_DECISION · CRITICAL
Impact 96% · Confidence 94%