Agent RBAC & namespace policies

Shipped in v3-alpha (Beta). Extends workspace-level RLS to per-agent scopes within a workspace. Interfaces may still change before 3.0 stable.

Why per-agent (not just per-workspace)

v2 enforces tenant isolation at the workspace level via PostgreSQL RLS FORCE. That’s enough for SaaS multi-tenancy. But inside one workspace, agents may serve different functions: one is allowed to write facts, another only reads; one can delegate tasks, another can’t.

The permission model

interface AgentMemoryAccess {
  agentId: string;
  workspaceId: string;
 
  // What can be read
  readScopes: MemoryScope[];
 
  // What can be written
  writeScopes: MemoryScope[];
 
  // Self-editing permissions
  selfEdit: SelfEditPolicy;
 
  // Task permissions
  taskScopes: {
    canCreate: boolean;
    canDelegate: boolean;
    canDelegateTo: string[];  // specific agent IDs, or "*"
  };
 
  // Rate limits
  limits: {
    maxRecallsPerMinute: number;
    maxWritesPerMinute: number;
    maxSessionsConcurrent: number;
    maxSelfEditsPerSession: number;
  };
}

Scopes

type MemoryScope =
  | { kind: "all" }
  | { kind: "namespace"; namespace: string }
  | { kind: "type"; types: ("fact" | "decision" | "strategy" | ...)[] }
  | { kind: "entity"; entityIds: string[] };

Cache strategy

RBAC checks fire on every recall and every write. Cached per-agent in Redis hot tier with 60s TTL — invalidated on policy change.

See also