Rights-aware dashboard resource access
Dashboard resources are exposed through GetAvailableResourcesReply and surfaced in get_available_resources().
Current resource classes include:
- workspaces
- members
- models
- agents
- tools
- servers
- pending invites
Workspace-level data also includes:
- permission definitions
- current user permissions
12.1 Effective permission model
Permissions are defined in isa_dashboard/isa_dashboard_server_lib/src/routes/permissions.rs and enforced through require_permission().
Examples include:
manage_workspacemanage_rolesinvite_usersmanage_usersmanage_groupsmanage_group_membersmanage_modelsmanage_agentsmanage_toolsmanage_extensionsmanage_serverslink_resourcesview_feedbackdelete_feedback
12.2 Delegated user authority rule
Extensions must operate inside the authority of the current user.
An extension must not be treated as independently privileged.
Runtime access should be understood as:
text
allowed = user_has_rights
AND resource_is_visible_in_context
AND extension_manifest_declares_capability
AND host_policy_allows_extension_use12.3 Tools, servers, and future MCP
The dashboard model already includes tools and servers in workspace resources.
Extensions should only be allowed to use resources that are visible and allowed for the current user and workspace context.
If future extension-facing MCP/server invocation APIs are introduced, they must follow the same delegated-user authority model.
12.4 Model recommendation authority
Model recommendations do not grant authority to an extension. During the dashboard add flow, the acting administrator still needs manage_extensions to create the extension and manage_models to create selected missing models. Linking either resource to a group requires link_resources or the corresponding group manage_resources authority.
Every selected missing recommendation is first created in workspace inventory with no group links. The extension may be linked to the current group while its model remains workspace-only. Runtime access must therefore use the exact launch group's authorized resources and must never treat a recommendation as permission or as a workspace-wide fallback. See Model recommendations.