IGA

Permissions

CoreLink uses a direct resource:action grant model. Permissions are assigned to users or groups and scoped to a specific workspace (or tenant-wide for administrative actions). Each grant specifies a resource type (secrets, sessions, groups, audit, etc.) and an action (read, write, admin, approve). The RBAC engine evaluates grants as a triple: (subject, action, resource).

Permission grants support expiration dates for time-limited access and can be filtered by environment within a workspace.

Permissions screenshot

Key Configuration

  • Grant scope (workspace, tenant-wide)
  • Resource types and actions
  • Expiration policy
  • Environment filter
All documentation Question about this? Talk to us