RBAC & access¶
Daedalus is multi-user. Identity comes from single sign-on first, with a local
fallback, and every route is gated by a feature at a level (none /
view / edit).
Roles¶
Four roles ship out of the box, from most to least privileged:
| Role | Intent |
|---|---|
| Administrator | full control, including user/role management and audit |
| Engineer | run engagements, deploy and manage agents, edit most features |
| Analyst | view findings and coverage, run reports; limited edit |
| Viewer | read-only across the console |
Roles map to an itemized feature matrix — board projects, board reset, tool install, LAN sandbox, findings/flags, reports, agents, BAS, audit, and more — so permissions are granted per capability, not as a coarse tier. A role simulator lets an admin preview exactly what any role sees.
Identity¶
- SSO first. An access assertion from the identity-aware proxy is verified against the team's key set and expected audience, then trusted. A first-time SSO user is auto-provisioned at a configurable default role.
- Local fallback. A username / password session is available where SSO isn't, with hashed credentials and a forced reset on first login for bootstrapped accounts.
- Internal identity. In-process service calls authenticate with a distinct internal token so background work (report generation, lookups) is authorized without borrowing a user's session.
Enforcement¶
A before_request gate maps each route to its (feature, level) and refuses
anything the caller's role doesn't cover. A @require(feature, level) decorator
guards individual handlers. The console mirrors this: it hides tabs and greys
controls to match the caller's role, so the UI never offers an action the backend
will reject.
Audit¶
Every state-changing action and every login is written to an append-only audit log, retained for compliance and exportable to CSV. Read-only poll traffic is excluded so the log stays signal, not noise, and each entry records the acting user, the action, and the originating client address.
Recovery valve
A break-glass environment switch disables all auth and acts as admin — for lockout recovery only. It is not a runtime mode you operate in.