RBAM
Resource-Based Access Management (RBAM) controls access across Acceldata AI Observability (AIO). AIO uses RBAM to ensure team members can view and change only the specific AIO projects they are explicitly granted access to. Instead of relying on a single tenant-wide role, access decisions are made on a per-project basis.
How It Works
RBAM secures access to your projects through a clear, multi-step authorization flow:
- Every AIO project is managed as an AIO Project resource and belongs to an AIO Project Group.
- Administrators assign users or user groups to an AIO Project Group with a designated role.
- When someone opens AIO, Acceldata checks with the authorization service to determine which AIO Project Groups the user can access.
- Resource administrators see every project in the tenant. All other users see only the projects contained within their assigned groups.
- If the authorization service cannot answer the request, AIO automatically denies access. It does not fail open.
Permissions and Roles
AIO project access is governed by two core permissions:
- View AIO project (view:aioProject): Allows users to list and open projects, read traces, and view rules.
- Modify AIO project (modify:aioProject): Allows users to update project details and create, edit, enable, or delete rules on that project.
Creating a project and deleting a project require Resource Administrator privileges. Granting group access alone is not sufficient for project creation or deletion because a project must exist before a group can be attached to it.
The following roles include AIO Project Management permissions:
- resource_owner: Grants View and Modify access.
- resource_editor: Grants View and Modify access.
- resource_viewer: Grants View access only.
- domain_manager: Grants View and Modify access on the assigned domain.
What People Can Do
User access varies based on assigned permissions and administrative privileges:
Access Level | Permitted Actions |
|---|---|
Resource Admin | Create and delete projects, with full access to every project across the tenant. |
Modify on a Group | Update assigned projects and manage rules on them. Cannot create or delete projects. |
View on a Group | Open assigned projects, read traces, and view rules. Cannot modify projects or rules. |
No Grant | The project is hidden and does not appear in the user interface. |
Setting Up Access Control
Setting up RBAM for AIO projects takes just a few steps in Acceldata access control:
- Open Acceldata access control.
- Create an AIO Project Group.
- Add your projects to the group.
- Assign users or user groups to the AIO Project Group using resource_owner, resource_editor, or resource_viewer.
A common setup pattern is to create separate groups based on environment—for example, one AIO Project Group for production projects and another for staging projects.
Managing rules follows the same project permissions: viewing rules requires View access, while creating or changing rules requires Modify access.
What's Next
To learn more about managing rules within your projects, visit the Rules page in this Governance section.

Have a suggestion?