Control-plane access

Who Can Change The AI Control Plane?

See how workspace roles, explicit business-group bindings, scoped workload keys, and accountable change events separate human and machine access.

What this answers

Transcript

The A.I. control plane can change provider routes, retention, policies, keys, and evidence. If human roles, business groups, and machine credentials drift into broad access, no audit log can make the operating model least-privilege after the fact. The first question is simple: who can change what, and why do they have that authority? Meridian's member inventory shows six people across four roles. Admins manage workspace configuration and access. An analyst can investigate operational evidence without inheriting every administrative power. A member participates in the workspace, while a viewer receives the narrowest read posture. The role beside each person is reviewable in one place. A role label is not enough. The Access and Roles reference spells out what each role grants and, just as importantly, what it does not. An analyst can investigate every request without reading captured bodies or changing settings. The backend remains the authorization authority; the interface is not used as a substitute for server-side enforcement. Group-to-role bindings turn business structure into a consistent default. Meridian maps Clinicians, Data Science, Security, and Support to distinct workspace roles. These seeded groups are manual bindings in this demo. They show the operating model without claiming that a live directory sync or immediate provisioning event occurred. People are only one identity boundary. Workloads use scoped access keys that can be named, expired, revoked, and reviewed independently. A patient triage application and an insurance batch job should not share one permanent credential merely because they share a workspace. Separating human authority from workload identity makes each change smaller and easier to explain. Least privilege becomes credible when denied access is evidence too. The unified configuration log can preserve role changes, key lifecycle events, policy changes, and denied-access records. A reviewer can ask which subject changed, who acted, when it happened, and whether the attempt was allowed—without merging every control into one opaque admin role. The resulting model is practical: people receive the role their work requires, business groups keep assignments consistent, workloads receive their own revocable credentials, and each material change leaves an accountable record. PrivacyFirst does not call manual bindings a live directory integration. It shows exactly which boundary is configured today. Bring us your identity groups and one service credential. We will map a least-privilege operating model for the people and workloads that can change your A.I. control plane. Book a live demo at PrivacyFirst dot A.I.