Skip to content

RBAC & access

Daedalus is multi-user. Identity comes from single sign-on first, with a local fallback, and every route is gated by a feature at a level (none / view / edit).

Roles

Four roles ship out of the box, from most to least privileged:

Role Intent
Administrator full control, including user/role management and audit
Engineer run engagements, deploy and manage agents, edit most features
Analyst view findings and coverage, run reports; limited edit
Viewer read-only across the console

Roles map to an itemized feature matrix — board projects, board reset, tool install, LAN sandbox, findings/flags, reports, agents, BAS, audit, and more — so permissions are granted per capability, not as a coarse tier. A role simulator lets an admin preview exactly what any role sees.

Identity

  • SSO first. An access assertion from the identity-aware proxy is verified against the team's key set and expected audience, then trusted. A first-time SSO user is auto-provisioned at a configurable default role.
  • Local fallback. A username / password session is available where SSO isn't, with hashed credentials and a forced reset on first login for bootstrapped accounts.
  • Internal identity. In-process service calls authenticate with a distinct internal token so background work (report generation, lookups) is authorized without borrowing a user's session.

Enforcement

A before_request gate maps each route to its (feature, level) and refuses anything the caller's role doesn't cover. A @require(feature, level) decorator guards individual handlers. The console mirrors this: it hides tabs and greys controls to match the caller's role, so the UI never offers an action the backend will reject.

Audit

Every state-changing action and every login is written to an append-only audit log, retained for compliance and exportable to CSV. Read-only poll traffic is excluded so the log stays signal, not noise, and each entry records the acting user, the action, and the originating client address.

Recovery valve

A break-glass environment switch disables all auth and acts as admin — for lockout recovery only. It is not a runtime mode you operate in.