Works with the AI tools you already use
Access Control Architect — Design Roles & Permissions
Access Control Architect — Design Roles, Permissions & Authorization: model least-privilege access and test policy decisions.
$9.99
Access Control Architect — Design Roles & Permissions
Example session with this skill installed
We are building a multi-tenant project management SaaS. Users can belong to multiple organizations. Owners invite members, assign roles, create projects, and share individual reports with external guests. Support staff can help customers but must not read customer data by default. Propose an authorization model, identify high-risk gaps, and give us a focused test plan.
- Read your context and instructions
- Compiled the access control architect
- Generated the document
Recommended model
Use RBAC for stable organization-level capabilities and ReBAC for project/report relationships. Add ABAC only for trusted context such as support approval, resource sensitivity, or time-bounded elevation. Treat tenant membership as a verified server-side relationship.
Core policy map
| Subject | Action | Resource and scope | Decision rule |
|---|---|---|---|
| Organization owner | invite member, assign role | Own organization | Allow within the owner’s organization; block granting privileges above the owner’s delegation boundary. |
| Organization member | read project | Project in active organization | Allow only when current membership and project tenancy both match. |
| Project editor | update project | Assigned project | Allow for explicit editor relationship; reject client-supplied tenant or owner IDs as authority. |
| Report guest | read shared report | Specifically shared report | Allow read-only access while the share is active; deny sibling reports and administrative actions. |
| Support operator | access customer record | Customer tenant | Deny by default. Require approved, time-limited, scoped access with a reason and audit record. |
Enforcement and risks
Enforce every decision in the service/API layer, including object and export endpoints. UI hiding is not a control. Resolve tenant membership and resource relationships from trusted data. Keep role assignment separate from role definition and log grants, revocations, support elevation and sensitive reads.
Test cases
- A member cannot read a project in an organization they do not belong to.
- Changing a report ID cannot expose another tenant’s report.
- A guest can read only the report explicitly shared with them.
- An owner cannot grant a role above their delegation scope.
- Support access is denied without approval and expires at its configured time.
- Removing membership revokes access on the next authoritative check.
Assumptions to confirm
Define whether owners can share outside their organization, how quickly membership changes propagate, and who may approve support access. Validate the model against your actual data schema and enforcement code before rollout.
access-control-architect-design-roles-pe.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
Access Control Architect turns product requirements into explicit, least-privilege authorization designs. Use it to model roles and permissions, compare RBAC, ABAC, ReBAC and ACL approaches, define tenant and resource boundaries, review API or object-level checks, plan safe delegation, and build positive and negative policy tests.
The workflow separates authentication from authorization and treats server-side enforcement as authoritative. It makes assumptions visible when requirements are incomplete, maps subjects, actions, resources, relationships and context, then produces an implementation-ready policy model with enforcement points, migration steps, tests and governance guidance.
Use it for SaaS, APIs, internal tools, data platforms, AI agents and multi-tenant products. It works from the requirements, diagrams, code excerpts or configuration you provide; it does not claim live access to repositories, IAM consoles, logs or cloud environments.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean today
- Passed all security checks, Safe to install