Permissions
Permissions
Section titled “Permissions”Complete reference for all permissions available in Mantis RBAC system.
Overview
Section titled “Overview”Mantis uses a resource:action permission model with 111 predefined permissions covering all system resources.
Permission Structure
Section titled “Permission Structure”| Component | Description | Examples |
|---|---|---|
| Resource | The entity being accessed | deployments, targets, users |
| Action | The operation being performed | create, read, update, delete |
| Name | Combined identifier | deployments:create |
Permission Categories
Section titled “Permission Categories”Actions
Section titled “Actions”Manage deployment actions (scripts, commands).
| Permission | Description |
|---|---|
actions:create | Create new actions |
actions:read | View actions and versions |
actions:update | Modify existing actions |
actions:delete | Delete actions |
Sequences
Section titled “Sequences”Manage deployment sequences.
| Permission | Description |
|---|---|
sequences:create | Create new sequences |
sequences:read | View sequences and versions |
sequences:update | Modify existing sequences |
sequences:delete | Delete sequences |
Solutions
Section titled “Solutions”Manage deployment solutions.
| Permission | Description |
|---|---|
solutions:create | Create new solutions |
solutions:read | View solutions and versions |
solutions:update | Modify existing solutions |
solutions:delete | Delete solutions |
Targets
Section titled “Targets”Manage deployment targets.
| Permission | Description |
|---|---|
targets:create | Register new targets |
targets:read | View target information |
targets:update | Modify target settings |
targets:delete | Remove targets |
Deployments
Section titled “Deployments”Manage deployment execution.
| Permission | Description |
|---|---|
deployments:create | Start new deployments |
deployments:read | View deployment status and history |
deployments:update | Modify deployment settings |
deployments:cancel | Cancel running deployments |
deployments:trigger | Trigger deployments |
deployments:override_freeze | Deploy despite an active freeze |
Environments
Section titled “Environments”Manage deployment environments.
| Permission | Description |
|---|---|
environments:create | Create new environments |
environments:read | View environments |
environments:update | Modify environment settings |
environments:delete | Delete environments |
environments:manage_targets | Assign/remove targets in environments |
Manage resource tags.
| Permission | Description |
|---|---|
tags:create | Create new tags |
tags:read | View tags |
tags:update | Modify tags |
tags:delete | Delete tags |
Storage
Section titled “Storage”Manage storage backends.
| Permission | Description |
|---|---|
storage:create | Upload packages/artifacts |
storage:read | View and download packages |
storage:update | Modify storage configurations |
storage:delete | Delete packages |
storage:test | Test storage connections |
Freezes
Section titled “Freezes”Manage deployment freezes.
| Permission | Description |
|---|---|
freezes:create | Create deployment freezes |
freezes:read | View deployment freezes |
freezes:update | Modify deployment freezes |
freezes:delete | Delete/end deployment freezes |
Promotions
Section titled “Promotions”Manage deployment promotions.
| Permission | Description |
|---|---|
promotions:create | Promote deployments between environments |
promotions:read | View promotion history |
promotions:update | Modify a pending promotion |
promotions:approve | Approve a pending promotion |
promotions:reject | Reject a pending promotion |
Rollbacks
Section titled “Rollbacks”Manage deployment rollbacks.
| Permission | Description |
|---|---|
rollbacks:create | Initiate deployment rollbacks |
rollbacks:read | View rollback history |
Certificates
Section titled “Certificates”Manage TLS certificates.
| Permission | Description |
|---|---|
certificates:create | Upload TLS certificates |
certificates:read | View certificates |
certificates:delete | Delete certificates |
Manage user accounts (admin).
| Permission | Description |
|---|---|
users:create | Create new user accounts |
users:read | View user accounts |
users:update | Modify user accounts |
users:delete | Delete user accounts |
Manage roles (admin).
| Permission | Description |
|---|---|
roles:create | Create new roles |
roles:read | List the users assigned to a role (role-users endpoint) |
roles:update | Modify role metadata |
roles:delete | Delete roles |
roles:manage | List/view roles and assign/remove their permissions |
Tenants
Section titled “Tenants”Manage tenants (system admin).
| Permission | Description |
|---|---|
tenants:create | Create new tenants |
tenants:read | View tenant information |
tenants:update | Modify tenant settings |
tenants:delete | Delete tenants |
tenants:manage_solutions | Assign solutions to tenants |
tenants:manage_tags | Assign tags to tenants |
tenants:manage_targets | Assign targets to tenants |
tenants:manage_variables | Manage tenant variables |
Registrations
Section titled “Registrations”Manage client registrations.
| Permission | Description |
|---|---|
registrations:create | Create client registrations |
registrations:read | View client registrations |
registrations:approve | Approve client registrations |
registrations:reject | Reject pending registrations |
registrations:revoke | Revoke client registrations |
registrations:delete | Delete registrations |
Registration Tokens
Section titled “Registration Tokens”Manage registration tokens.
| Permission | Description |
|---|---|
registration_tokens:create | Create registration tokens |
registration_tokens:read | View registration tokens |
registration_tokens:update | Update registration tokens |
registration_tokens:revoke | Revoke registration tokens |
registration_tokens:delete | Delete registration tokens |
Statistics
Section titled “Statistics”View system statistics.
| Permission | Description |
|---|---|
statistics:read | View system statistics |
Settings
Section titled “Settings”Manage system settings.
| Permission | Description |
|---|---|
settings:read | View system settings |
settings:manage | Modify system settings |
Encryption
Section titled “Encryption”Manage encryption keys.
| Permission | Description |
|---|---|
encryption:stats | View encryption statistics |
encryption:verify | Verify encryption key |
System
Section titled “System”System-level administration.
| Permission | Description |
|---|---|
system:admin | Full administrative access |
Manage the response/data cache.
| Permission | Description |
|---|---|
cache:read | View cache statistics |
cache:manage | Manage cache (clear, enable/disable) |
Notifications
Section titled “Notifications”Manage notification channels.
| Permission | Description |
|---|---|
notifications:create | Create notification channels |
notifications:read | View notification channels |
notifications:update | Modify notification channels |
notifications:delete | Delete notification channels |
Analysis
Section titled “Analysis”Manage AI-assisted deployment analysis.
| Permission | Description |
|---|---|
analysis:read | View analysis results and settings |
analysis:manage | Configure analysis providers/settings |
Failure Patterns
Section titled “Failure Patterns”View and manage recurring deployment-failure patterns.
| Permission | Description |
|---|---|
patterns:read | View failure patterns, cluster detail, and stats |
patterns:manage | Recompute, mute, resolve, and reactivate patterns |
Variable Sets
Section titled “Variable Sets”Manage reusable variable sets.
| Permission | Description |
|---|---|
variable_sets:create | Create new variable sets |
variable_sets:read | View variable sets |
variable_sets:update | Modify variable sets |
variable_sets:delete | Delete variable sets |
Config (Config-as-Code)
Section titled “Config (Config-as-Code)”Manage configuration-as-code repositories and sync.
| Permission | Description |
|---|---|
config:manage | Manage config-as-code repositories and sync |
config:set_authoritative | Mark a config repository as authoritative |
Access audit logs.
| Permission | Description |
|---|---|
audit:read | View audit log entries |
Schedules
Section titled “Schedules”Manage scheduled deployments.
| Permission | Description |
|---|---|
schedules:create | Create scheduled jobs |
schedules:read | View scheduled jobs |
schedules:update | Modify scheduled jobs |
schedules:delete | Delete scheduled jobs |
schedules:execute | Trigger a scheduled job now |
WireGuard
Section titled “WireGuard”Manage the WireGuard overlay network.
| Permission | Description |
|---|---|
wireguard:read | View WireGuard configuration/state |
wireguard:manage | Manage WireGuard configuration |
Thorax Instances
Section titled “Thorax Instances”Manage Thorax gRPC server instances.
| Permission | Description |
|---|---|
thorax_instances:read | View Thorax gRPC server instances |
thorax_instances:update | Modify Thorax instance settings |
thorax_instances:delete | Deregister Thorax instances |
API Operations
Section titled “API Operations”List All Permissions
Section titled “List All Permissions”Required permission: roles:manage.
curl -X GET \ -H "Authorization: Bearer $TOKEN" \ "https://api.mantis.local/api/v1/admin/permissions"Response:
[ { "resource": "actions", "permissions": [ { "id": "019b937d-4862-8ba3-98ce-0f03fba1c12d", "name": "actions:create", "resource": "actions", "action": "create", "description": "Create new actions" }, { "id": "019b937d-4862-892f-8964-135631fe2351", "name": "actions:read", "resource": "actions", "action": "read", "description": "View actions" } ] }, { "resource": "deployments", "permissions": [ { "id": "019b937d-4862-8e2a-88e4-d34627a858db", "name": "deployments:create", "resource": "deployments", "action": "create", "description": "Start new deployments" } ] }]Role Permission Assignments
Section titled “Role Permission Assignments”Default Role Permissions
Section titled “Default Role Permissions”Admin Role
Section titled “Admin Role”Has all (111) permissions assigned explicitly via the seed.
Operator Role
Section titled “Operator Role”| Resource | Permissions |
|---|---|
| actions | create, read, update |
| sequences | create, read, update |
| solutions | create, read, update |
| targets | create, read, update |
| deployments | create, read, cancel |
| environments | create, read, update, manage_targets |
| tags | create, read, update |
| storage | create, read, update, test |
| freezes | read, update |
| promotions | create, read |
| rollbacks | create, read |
| certificates | read |
| registrations | read |
| registration_tokens | read |
| statistics | read |
| roles | read |
| tenants | read |
| schedules | read, update, execute |
| thorax_instances | read, update |
| cache | read, manage |
| notifications | read, create, update |
| variable_sets | read, create, update |
| analysis | read |
| wireguard | read |
| patterns | read |
Viewer Role
Section titled “Viewer Role”| Resource | Permissions |
|---|---|
| actions | read |
| sequences | read |
| solutions | read |
| targets | read |
| deployments | read |
| environments | read |
| tags | read |
| storage | read |
| freezes | read |
| promotions | read |
| rollbacks | read |
| certificates | read |
| statistics | read |
| roles | read |
| tenants | read |
| schedules | read |
| thorax_instances | read |
| cache | read |
| notifications | read |
| variable_sets | read |
Tenant Admin Role
Section titled “Tenant Admin Role”The seed grants tenant_admin every permission except these five system-tier ones:
tenants:createtenants:deletesystem:adminsettings:manageaudit:read
This seeded permission set, however, is not the privilege ceiling for what a
tenant_admin (or any non-system-admin) may delegate to others.
Delegation ceiling (secure by default)
Section titled “Delegation ceiling (secure by default)”When a caller assigns roles/permissions to a user — or mints a role carrying
permissions — Mantis enforces a secure-by-default ceiling
(mandible/src/routes/admin/users.rs:67-126, roles.rs:45-69):
- A full system administrator (holding
system:admin) may confer anything. - Any other caller may confer only a permission it itself holds, or one
carried by the baseline tenant roles (
viewer/operator) — these are derived from the seed at call time (delegatable_permissions). - Everything else is refused — including any future system-tier permission.
A
tenant_admintherefore cannot grant itself the globaladminrole, mint a role carryingsystem:admin, or confer a newly-added dangerous permission it does not hold, even if such a permission is added later.
Permission Checking
Section titled “Permission Checking”How Permission Checks Work
Section titled “How Permission Checks Work”Permission Lookup Query
Section titled “Permission Lookup Query”-- Check if user has permissionSELECT COUNT(*) > 0FROM permissions pINNER JOIN roles_permissions rp ON rp.permission_id = p.idINNER JOIN users_roles ur ON ur.role_id = rp.role_idWHERE ur.user_id = $user_idAND p.name = $permission_name;Common Permission Combinations
Section titled “Common Permission Combinations”Deployment Operator
Section titled “Deployment Operator”Minimal permissions for running deployments:
[ "deployments:create", "deployments:read", "deployments:cancel", "solutions:read", "targets:read", "environments:read"]Solution Designer
Section titled “Solution Designer”Create and manage deployment content:
[ "actions:create", "actions:read", "actions:update", "sequences:create", "sequences:read", "sequences:update", "solutions:create", "solutions:read", "solutions:update", "storage:read", "storage:create"]Infrastructure Manager
Section titled “Infrastructure Manager”Manage targets and environments:
[ "targets:create", "targets:read", "targets:update", "targets:delete", "environments:create", "environments:read", "environments:update", "environments:manage_targets", "registrations:read", "registrations:approve", "registrations:revoke", "registration_tokens:create", "registration_tokens:read", "certificates:read"]Read-Only Auditor
Section titled “Read-Only Auditor”View everything without modification:
[ "actions:read", "sequences:read", "solutions:read", "targets:read", "deployments:read", "environments:read", "users:read", "roles:read", "tenants:read", "freezes:read", "promotions:read", "rollbacks:read", "registrations:read", "statistics:read", "settings:read"]Database Schema
Section titled “Database Schema”CREATE TABLE permissions ( id UUID PRIMARY KEY, name TEXT NOT NULL UNIQUE, resource TEXT NOT NULL, action TEXT NOT NULL, description TEXT, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP);
-- IndexesCREATE INDEX idx_permissions_name ON permissions(name);CREATE INDEX idx_permissions_resource ON permissions(resource);CREATE UNIQUE INDEX idx_permissions_resource_action ON permissions(resource, action);Permission Immutability
Section titled “Permission Immutability”To add new permissions:
- Create a database migration
- Insert new permission records
- Update role assignments as needed
- Rebuild and redeploy
Troubleshooting
Section titled “Troubleshooting”User Lacks Expected Permission
Section titled “User Lacks Expected Permission”-
Check user’s roles:
Terminal window curl -s -H "Authorization: Bearer $TOKEN" \https://api.mantis.local/api/v1/admin/users/$USER_ID/roles -
Check role’s permissions:
Terminal window curl -s -H "Authorization: Bearer $TOKEN" \https://api.mantis.local/api/v1/admin/roles/$ROLE_ID/permissions -
Verify permission exists:
Terminal window curl -s -H "Authorization: Bearer $TOKEN" \https://api.mantis.local/api/v1/admin/permissions | jq '.[].permissions[].name' | grep "target"
Permission Not Working
Section titled “Permission Not Working”- Check exact permission name - Must match exactly including colon
- Verify role assignment - User must have role with permission
- Check JWT claims - User ID must match database
Finding Required Permission
Section titled “Finding Required Permission”Check API documentation or handler code:
// In handlercheck_permission(&mut conn, audit, &auth.claims, "deployments:create").await?;Each endpoint documents its required permission in the OpenAPI spec.
Next Steps
Section titled “Next Steps”- Roles - Role configuration
- Users - User management
- RBAC Overview - System overview
