Agent RBAC & namespace policies
Shipped in v3-alpha (Beta). Extends workspace-level RLS to per-agent scopes within a workspace. Interfaces may still change before 3.0 stable.
Why per-agent (not just per-workspace)
v2 enforces tenant isolation at the workspace level via PostgreSQL RLS FORCE. That’s enough for SaaS multi-tenancy. But inside one workspace, agents may serve different functions: one is allowed to write facts, another only reads; one can delegate tasks, another can’t.
The permission model
interface AgentMemoryAccess {
agentId: string;
workspaceId: string;
// What can be read
readScopes: MemoryScope[];
// What can be written
writeScopes: MemoryScope[];
// Self-editing permissions
selfEdit: SelfEditPolicy;
// Task permissions
taskScopes: {
canCreate: boolean;
canDelegate: boolean;
canDelegateTo: string[]; // specific agent IDs, or "*"
};
// Rate limits
limits: {
maxRecallsPerMinute: number;
maxWritesPerMinute: number;
maxSessionsConcurrent: number;
maxSelfEditsPerSession: number;
};
}Scopes
type MemoryScope =
| { kind: "all" }
| { kind: "namespace"; namespace: string }
| { kind: "type"; types: ("fact" | "decision" | "strategy" | ...)[] }
| { kind: "entity"; entityIds: string[] };Cache strategy
RBAC checks fire on every recall and every write. Cached per-agent in Redis hot tier with 60s TTL — invalidated on policy change.
See also
- Self-editing memory — gated by selfEdit policy
- Tasks & events — delegation gated by taskScopes