Skip to content

Rights-aware dashboard resource access ​

Dashboard resources are exposed through GetAvailableResourcesReply and surfaced in get_available_resources().

Current resource classes include:

  • workspaces
  • members
  • models
  • agents
  • tools
  • servers
  • pending invites

Workspace-level data also includes:

  • permission definitions
  • current user permissions

12.1 Effective permission model ​

Permissions are defined in isa_dashboard/isa_dashboard_server_lib/src/routes/permissions.rs and enforced through require_permission().

Examples include:

  • manage_workspace
  • manage_roles
  • invite_users
  • manage_users
  • manage_groups
  • manage_group_members
  • manage_models
  • manage_agents
  • manage_tools
  • manage_extensions
  • manage_servers
  • link_resources
  • view_feedback
  • delete_feedback

12.2 Delegated user authority rule ​

Extensions must operate inside the authority of the current user.

An extension must not be treated as independently privileged.

Runtime access should be understood as:

text
allowed = user_has_rights
       AND resource_is_visible_in_context
       AND extension_manifest_declares_capability
       AND host_policy_allows_extension_use

12.3 Tools, servers, and future MCP ​

The dashboard model already includes tools and servers in workspace resources.

Extensions should only be allowed to use resources that are visible and allowed for the current user and workspace context.

If future extension-facing MCP/server invocation APIs are introduced, they must follow the same delegated-user authority model.

12.4 Model recommendation authority ​

Model recommendations do not grant authority to an extension. During the dashboard add flow, the acting administrator still needs manage_extensions to create the extension and manage_models to create selected missing models. Linking either resource to a group requires link_resources or the corresponding group manage_resources authority.

Every selected missing recommendation is first created in workspace inventory with no group links. The extension may be linked to the current group while its model remains workspace-only. Runtime access must therefore use the exact launch group's authorized resources and must never treat a recommendation as permission or as a workspace-wide fallback. See Model recommendations.

ISA Warden extension specification