← Overview

Governance

Every permission, every action, every euro, per project

The project is graal’s unit of governance. It is where you set who may do what, where you read who did what, person or agent, and where you follow what it costs. Your directory remains the source of identities.

Role assignments of an organization in the graal console: for each holder, user or agent, the role, the resource it applies to (a project or the organization), the date it was granted and a “Révoquer” button. The first row is the agent-mcp service account, marked “Agent”.

Role assignments: every permission has a holder, a resource and a date, and is revoked in the same place, whether a person or an agent holds it.

Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).

Key capabilities

Control, trace, manage

Fine-grained permissions

Roles per project and per resource, granted to a person, a group or an agent, and revocable in one click.

Your directory, your SSO

OIDC, SAML, LDAP or Active Directory: identities and groups come from your side, and strong authentication can be enforced per organization.

A complete audit trail

Every API action is logged: author, person or agent, action, resource, result and source address. The trail can be exported.

Encrypted secrets

Passwords, keys and tokens encrypted at rest (AES-GCM), delivered to runs at execution time and never shown in clear again.

Quotas and costs per project

vCPU, memory and GPU quotas checked before every run; the cost of each run is charged to its project.

Human approvals

A sensitive action, such as scheduling in production, can wait for a manager’s approval before it runs.

How it works

Governance that follows the project

  1. Step 01

    Federate identities

    You connect your directory or your SSO provider. Groups become role holders.

  2. Step 02

    Assign

    Each person, group or agent receives a role on the organization, a project or a specific resource.

  3. Step 03

    Control

    Audit, costs and quotas are read per project; sensitive actions wait for approval.

One permission model, for every path

The console, the REST API, the MCP server, notebooks and SQL all go through the same access control. A permission withdrawn is withdrawn everywhere at once: there is no side path that would keep access open.

Standards and integrations

Your identity standards

  • OIDC
  • SAML
  • LDAP
  • Active Directory
  • Keycloak
  • AES-GCM

Governance

What your CISO checks

  • No implicit permission: every access goes through an assigned role
  • An agent is a service account, with its own roles, revocable like a user
  • The audit trail can be read and exported without third-party tools

Frequently asked questions

Can we use our existing directory?

Yes: LDAP, Active Directory, or any OIDC or SAML provider. graal does not become a second source of identities.

Do agents have separate permissions?

They have their own permissions, never those of the person who created them. An agent is a service account with a role on a project.

How is a project’s cost calculated?

From the resources reserved by its runs and your organization’s price list, run by run.

Review your permissions in a demonstration

Roles, audit and costs on a demonstration project, with an agent among the role holders.