Skip to main content

Access Tiers Overview

OSSA Access Tiers - permission levels for agent capabilities

Access Tiers Overview

OSSA defines four access tiers that control agent permissions and capabilities:

TierLevelDescription
observerRead-onlyQuery-only access, no state changes
operatorStandardExecute capabilities, tool calls
adminElevatedSystem configuration, agent management
systemFullUnrestricted access (internal only)

Configuration

apiVersion: ossa/v0.4.9 kind: Agent spec: access_tier: operator # Default tier capabilities: - name: read_data access_tier: observer - name: update_record access_tier: operator - name: manage_agents access_tier: admin

Permission Inheritance

Access tiers form a hierarchy:

system > admin > operator > observer

Higher tiers inherit permissions from lower tiers.