> ## Documentation Index
> Fetch the complete documentation index at: https://docs.varios-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Who can do what in VARIOS AI

> How roles from the identity provider and groups control access in VARIOS AI.

VARIOS AI controls access through **four fixed roles** and through **groups**. Roles define which areas a person may administer. Groups define which assistants, AI models and connectors their members may use.

## Roles

| Role | Value in the identity provider | Purpose |
| - | - | - |
| **User** | none, see [Who can sign in](#who-can-sign-in) | Chat, create own assistants, manage own settings. Every signed-in person has this role. |
| **Admin** | Value of `ADMIN_GROUP_NAME` | Manage users, groups, global assistants, knowledge bases and API keys, view the admin dashboard. |
| **SuperAdmin** | Value of `SUPERADMIN_GROUP_NAME` | Everything Admin can do, plus models, connectors, credentials, prompt library, settings, updates and technical logs. |
| **ComplianceAdmin** | Value of `COMPLIANCE_ADMIN_GROUP_NAME` | View the DLP dashboard and compliance logs. |

**SuperAdmin** has no access to the DLP dashboard and the compliance logs. These areas are reserved for the **ComplianceAdmin** role. This keeps oversight of usage separate from technical administration.

A person can hold several roles, for example **Admin** and **ComplianceAdmin**.

## Where roles come from

Roles are assigned exclusively in the **identity provider**, not in VARIOS AI.

| Identity provider | Assignment |
| - | - |
| Microsoft Entra ID | App roles of the enterprise application, see [Set up Microsoft Entra ID](../installation/microsoft-entra-id) |
| Keycloak | Groups named as in the `.env`, see [Set up Keycloak](../installation/keycloak#map-administrator-roles) |

VARIOS AI takes the roles from the token again at **every sign-in**. A role removed in the identity provider is therefore also removed in VARIOS AI after the next sign-in.

<Note>
  Role changes take effect when the person signs in again.
</Note>

## Who can sign in

There is no separate role and no `.env` variable for regular users. Every person who signs in successfully through the identity provider can use VARIOS AI as **User**. You therefore control who can sign in in the identity provider:

| Identity provider | Control | Details |
| - | - | - |
| Microsoft Entra ID | **Assignment required** setting of the enterprise application | [User access in Microsoft Entra ID](../installation/microsoft-entra-id#user-access) |
| Keycloak | Users in the realm | [User access in Keycloak](../installation/keycloak#user-access) |

With Microsoft Entra ID, you can additionally restrict sign-in to users with the `UserLoginAllowed` role. To do so, enable the setting **Allow login only for users with the UserLoginAllowed role (from Microsoft Entra ID group claim)** under [General](./settings/general). The check also applies to administrators.

<Warning>
  Only assign the administrator roles to users and groups that should have administrator rights. If the group containing all VARIOS AI users receives an administrator role, all of its members become administrators.
</Warning>

## What each role sees in the admin menu

| Area | Admin | SuperAdmin | ComplianceAdmin |
| - | - | - | - |
| Dashboard | Yes | Yes | — |
| Billing (prepaid only) | Yes | Yes | — |
| Users | Yes | Yes, plus start synchronization | — |
| Groups | Yes | Yes, plus block a group from signing in | — |
| Global assistants | Yes | Yes | — |
| Knowledge bases (with embedding model) | Yes | Yes | — |
| API keys | Yes | Yes | — |
| Prompt library | — | Yes | — |
| Connectors | — | Yes | — |
| Models | — | Yes | — |
| Credentials | — | Yes | — |
| Logs: system, security, SCIM | — | Yes | — |
| Service status | — | Yes | — |
| Settings and updates | — | Yes | — |
| Compliance: DLP dashboard | — | — | Yes |
| Compliance: audit, sign-in, DLP and connector logs | — | — | Yes |

## Groups

With [groups](./groups), admins control which resources members may use:

* **Group assistants**: global assistants available to the members
* **Group AI models**: models the members may use
* **Group connectors**: connectors allowed within the group
* **Maximum costs per month**: cost limit for the whole group

Groups and memberships usually come from the identity provider via synchronization. Groups do not grant admin rights; those come from roles only.

## Recommendations

* Assign **SuperAdmin** to only a few people and **Admin** for day-to-day administration.
* Assign **ComplianceAdmin** to people who are not also SuperAdmin, so that oversight and administration stay separate.
* Control access to models, assistants and connectors through groups rather than individual people.
* Review role assignments in the identity provider regularly.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.