Roles
SuperAdmin has no access to the DLP dashboard and the compliance logs. These areas are reserved for the ComplianceAdmin role. This keeps oversight of usage separate from technical administration.
A person can hold several roles, for example Admin and ComplianceAdmin.
Where roles come from
Roles are assigned exclusively in the identity provider, not in VARIOS AI.
VARIOS AI takes the roles from the token again at every sign-in. A role removed in the identity provider is therefore also removed in VARIOS AI after the next sign-in.
Role changes take effect when the person signs in again.
Who can sign in
There is no separate role and no.env variable for regular users. Every person who signs in successfully through the identity provider can use VARIOS AI as User. You therefore control who can sign in in the identity provider:
With Microsoft Entra ID, you can additionally restrict sign-in to users with the
UserLoginAllowed role. To do so, enable the setting Allow login only for users with the UserLoginAllowed role (from Microsoft Entra ID group claim) under General. The check also applies to administrators.
What each role sees in the admin menu
Groups
With groups, admins control which resources members may use:- Group assistants: global assistants available to the members
- Group AI models: models the members may use
- Group connectors: connectors allowed within the group
- Maximum costs per month: cost limit for the whole group
Recommendations
- Assign SuperAdmin to only a few people and Admin for day-to-day administration.
- Assign ComplianceAdmin to people who are not also SuperAdmin, so that oversight and administration stay separate.
- Control access to models, assistants and connectors through groups rather than individual people.
- Review role assignments in the identity provider regularly.
