Fine-grained permissions
Roles per project and per resource, granted to a person, a group or an agent, and revocable in one click.
Governance
The project is graal’s unit of governance. It is where you set who may do what, where you read who did what, person or agent, and where you follow what it costs. Your directory remains the source of identities.

Role assignments: every permission has a holder, a resource and a date, and is revoked in the same place, whether a person or an agent holds it.
Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).
Key capabilities
Roles per project and per resource, granted to a person, a group or an agent, and revocable in one click.
OIDC, SAML, LDAP or Active Directory: identities and groups come from your side, and strong authentication can be enforced per organization.
Every API action is logged: author, person or agent, action, resource, result and source address. The trail can be exported.
Passwords, keys and tokens encrypted at rest (AES-GCM), delivered to runs at execution time and never shown in clear again.
vCPU, memory and GPU quotas checked before every run; the cost of each run is charged to its project.
A sensitive action, such as scheduling in production, can wait for a manager’s approval before it runs.
How it works
Step 01
You connect your directory or your SSO provider. Groups become role holders.
Step 02
Each person, group or agent receives a role on the organization, a project or a specific resource.
Step 03
Audit, costs and quotas are read per project; sensitive actions wait for approval.
The console, the REST API, the MCP server, notebooks and SQL all go through the same access control. A permission withdrawn is withdrawn everywhere at once: there is no side path that would keep access open.
Standards and integrations
Governance
Yes: LDAP, Active Directory, or any OIDC or SAML provider. graal does not become a second source of identities.
They have their own permissions, never those of the person who created them. An agent is a service account with a role on a project.
From the resources reserved by its runs and your organization’s price list, run by run.
Roles, audit and costs on a demonstration project, with an agent among the role holders.