Skip to main content
VARIOS AI controls access through four fixed roles and through groups. Roles define which areas a person may administer. Groups define which assistants, AI models and connectors their members may use.

Roles

SuperAdmin has no access to the DLP dashboard and the compliance logs. These areas are reserved for the ComplianceAdmin role. This keeps oversight of usage separate from technical administration. A person can hold several roles, for example Admin and ComplianceAdmin.

Where roles come from

Roles are assigned exclusively in the identity provider, not in VARIOS AI. VARIOS AI takes the roles from the token again at every sign-in. A role removed in the identity provider is therefore also removed in VARIOS AI after the next sign-in.
Role changes take effect when the person signs in again.

Who can sign in

There is no separate role and no .env variable for regular users. Every person who signs in successfully through the identity provider can use VARIOS AI as User. You therefore control who can sign in in the identity provider: With Microsoft Entra ID, you can additionally restrict sign-in to users with the UserLoginAllowed role. To do so, enable the setting Allow login only for users with the UserLoginAllowed role (from Microsoft Entra ID group claim) under General. The check also applies to administrators.
Only assign the administrator roles to users and groups that should have administrator rights. If the group containing all VARIOS AI users receives an administrator role, all of its members become administrators.

What each role sees in the admin menu

Groups

With groups, admins control which resources members may use:
  • Group assistants: global assistants available to the members
  • Group AI models: models the members may use
  • Group connectors: connectors allowed within the group
  • Maximum costs per month: cost limit for the whole group
Groups and memberships usually come from the identity provider via synchronization. Groups do not grant admin rights; those come from roles only.

Recommendations

  • Assign SuperAdmin to only a few people and Admin for day-to-day administration.
  • Assign ComplianceAdmin to people who are not also SuperAdmin, so that oversight and administration stay separate.
  • Control access to models, assistants and connectors through groups rather than individual people.
  • Review role assignments in the identity provider regularly.