Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Access Control Architect — Design Roles & Permissions

    1

    Access Control Architect — Design Roles, Permissions & Authorization: model least-privilege access and test policy decisions.

    $9.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Access Control Architect — Design Roles & Permissions

    Access Control Architect — Design Roles & Permissions

    Example session with this skill installed

    We are building a multi-tenant project management SaaS. Users can belong to multiple organizations. Owners invite members, assign roles, create projects, and share individual reports with external guests. Support staff can help customers but must not read customer data by default. Propose an authorization model, identify high-risk gaps, and give us a focused test plan.

    • Read your context and instructions
    • Compiled the access control architect
    • Generated the document

    Recommended model

    Use RBAC for stable organization-level capabilities and ReBAC for project/report relationships. Add ABAC only for trusted context such as support approval, resource sensitivity, or time-bounded elevation. Treat tenant membership as a verified server-side relationship.

    Core policy map

    SubjectActionResource and scopeDecision rule
    Organization ownerinvite member, assign roleOwn organizationAllow within the owner’s organization; block granting privileges above the owner’s delegation boundary.
    Organization memberread projectProject in active organizationAllow only when current membership and project tenancy both match.
    Project editorupdate projectAssigned projectAllow for explicit editor relationship; reject client-supplied tenant or owner IDs as authority.
    Report guestread shared reportSpecifically shared reportAllow read-only access while the share is active; deny sibling reports and administrative actions.
    Support operatoraccess customer recordCustomer tenantDeny by default. Require approved, time-limited, scoped access with a reason and audit record.

    Enforcement and risks

    Enforce every decision in the service/API layer, including object and export endpoints. UI hiding is not a control. Resolve tenant membership and resource relationships from trusted data. Keep role assignment separate from role definition and log grants, revocations, support elevation and sensitive reads.

    Test cases

    1. A member cannot read a project in an organization they do not belong to.
    2. Changing a report ID cannot expose another tenant’s report.
    3. A guest can read only the report explicitly shared with them.
    4. An owner cannot grant a role above their delegation scope.
    5. Support access is denied without approval and expires at its configured time.
    6. Removing membership revokes access on the next authoritative check.

    Assumptions to confirm

    Define whether owners can share outside their organization, how quickly membership changes propagate, and who may approve support access. Validate the model against your actual data schema and enforcement code before rollout.

    access-control-architect-design-roles-pe.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    Access Control Architect turns product requirements into explicit, least-privilege authorization designs. Use it to model roles and permissions, compare RBAC, ABAC, ReBAC and ACL approaches, define tenant and resource boundaries, review API or object-level checks, plan safe delegation, and build positive and negative policy tests.

    The workflow separates authentication from authorization and treats server-side enforcement as authoritative. It makes assumptions visible when requirements are incomplete, maps subjects, actions, resources, relationships and context, then produces an implementation-ready policy model with enforcement points, migration steps, tests and governance guidance.

    Use it for SaaS, APIs, internal tools, data platforms, AI agents and multi-tenant products. It works from the requirements, diagrams, code excerpts or configuration you provide; it does not claim live access to repositories, IAM consoles, logs or cloud environments.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean today

    • Passed all security checks, Safe to install

    Listedtoday

    What's inside

    Frequently Asked Questions