Skip to main content

Role-Based Access Control

User Management

Roles

Permission Levels

Source-Level Access

  • Which data sources a user can query
  • Finance team accesses financial databases; Operations accesses logistics databases

Table-Level Access

  • Which tables within a source are visible
  • The salary table is restricted to HR and executives

Column-Level Security

  • Hide sensitive columns from specific roles
  • Individual salary amounts hidden from non-managers; department averages remain visible

Row-Level Security

  • Automatically filter data based on user context
  • Regional managers see only their region’s data; business unit heads see only their unit’s metrics

Permission Enforcement

Permissions are enforced at the query planning stage, before any SQL is generated or data is accessed.
1

Classify Question

The Main Agent classifies the question and identifies required data concepts (tables, columns, metrics)
2

Check Permissions

The permission engine checks: does this user have access to the required sources, tables, and columns?
3

Apply Row Filters

If permitted, row-level filters are automatically injected into the query based on the user’s context
4

Generate or Restrict

If fully permitted: query is generated and executed with row-level filters applied. If partially permitted: response is restricted to permitted data, with an explanation of what is restricted. If not permitted: the system explains what it cannot access.
Enforcement operates on the resolved query plan, not the natural language input. Rephrasing a question does not bypass permissions.

Inference Attack Protection

Aggregation queries over small groups could potentially reveal individual records (e.g., average salary in a one-person department). Superatom applies cardinality checks:
  • Aggregations are suppressed for groups below a configurable minimum record count (default: 5)
  • If a query would produce an aggregation over too few rows, the system either suppresses that group or returns a broader aggregation

Permission Matrix


SSO Integration

Superatom delegates authentication to the customer’s existing identity infrastructure:

Supported Identity Providers

  • Okta
  • Microsoft Azure AD / Entra ID
  • OneLogin
  • Any SAML 2.0 or OpenID Connect compliant provider

User Deprovisioning

Disabling a user in the identity provider immediately revokes their Superatom access. No separate deprovisioning step is required.

Dashboard & Report Sharing

Every dashboard and report has its own sharing controls: Share with specific users by email, with entire roles, or via public link (optional, for non-sensitive dashboards).

Mobile Access Control

Mobile apps inherit the same permission model:
  • Role-based views (executives see KPIs, managers see team metrics, field workers see task-specific views)
  • Biometric authentication (Face ID, Touch ID, fingerprint) required
  • Automatic session timeout
  • MDM (Mobile Device Management) compatible

Next Steps

Agent Security Model

How agent isolation protects data access

Action Safety

Approval gates for write-back operations