Skip to main content
Documentation
Docs / Products / Access
Agent setup

Control

Access

Compare expected access with observations across roles, tenants, and actions to identify permission mismatches.

Last updated August 22, 2026

Find where observed permissions disagree with the rules.

Use cases

Make expected access explicit

Describe who should be able to perform each action.

Expose mismatches

Compare observed permissions with the expected contract, including cross-tenant cases.

Keep the evidence attached

Retain the observations needed to investigate a permission finding.

How it works

  1. 1

    Define expected access

    Supply roles, organizations, and allowed or denied actions.

  2. 2

    Supply observations

    Add the access results gathered by your tests.

  3. 3

    Investigate differences

    Review mismatches and rerun the relevant tests after a repair.

Quickstart

Open Access in the console, provide the required inputs, and start an organization scoped run.

Inputs

  • roles and tenants
  • identity fixtures
  • UI, API, and data probes
  • approved authorization contract

Outputs

  • permission matrix
  • cross-tenant exploit evidence
  • privilege drift
  • release gate verdict
Open Access

MCP

Call Access from a compatible agent with the preferred public tool name.

bashReady
symbolic.access.run

The previous internal service identifier remains accepted for compatibility, but new integrations should use this product name.