Skip to content

Governance & access

RebelCore applies several controls to determine who can work with data and what Agent may display. Administrators should configure these controls to match the organisation’s policies and each user’s responsibilities.

Controls at a glance

ControlWhat it decides
Account responsibilityAccess reserved for the Customer Super Admin, Data Protection Officer, or Security Officer.
Role permissionsWhich product pages and actions a user can use.
Project accessWhich projects a user can open.
LLM exposure levelHow much dataset detail Agent may return.
Mask to AIWhether personal identifiers are replaced before AI processing.
Mask on interfaceWhether authorised personal information is shown in Agent.
Audit and ActivityWhich Agent and administrative records can be reviewed.

These controls are cumulative. For example, Access Agent lets a user open Agent, but the user can only select datasets from projects they are allowed to access.

Roles and permissions

Each portal user is assigned one role. A role can allow actions such as:

  • Viewing or importing datasets.
  • Building modules.
  • Creating projects.
  • Opening the Tree.
  • Building or deleting semantic datasets.
  • Using Agent.
  • Managing users or roles.

Use Roles & permissions for the full list.

Project access

Projects can be available to:

  • All Users in the organisation, subject to role permissions.
  • A Restricted Access list of selected users.

Use restricted access for projects containing sensitive or need-to-know data. Review the granted list whenever team membership or responsibilities change.

Agent output controls

Every module has an LLM exposure level:

  • Full can permit exact authorised data.
  • Limited permits analysis and summaries without source records.
  • Advisory only permits qualitative guidance without dataset values or statistics.

For projects or Agent selections containing multiple modules, the most restrictive level applies.

Personal-information controls

Agent provides two separate controls:

  • Mask to AI replaces personal identifiers before they are sent for AI processing. It is fixed after the first prompt in a session.
  • Mask on interface controls whether the user sees authorised personal information in the conversation. It can be changed during a session.

Customer Super Admins can require Mask to AI for the organisation. When required, Agent users cannot turn it off.

See RebelCore Agent for usage instructions.

Administrative review

  • Audit lets the Customer Super Admin review Agent users, sessions, conversations, and recorded activity.
  • Activity provides a chronological record of important user and administrative actions.
  • HITL supports the review of interactions that require a person to decide whether work may continue.
  • Login Activity supports account-access review by authorised governance users.

Access to these areas depends on account responsibility and role.

Example separation of duties

ResponsibilityTypical access
Data stewardImport datasets, build modules, and maintain source quality.
Project analystCreate projects, curate the Tree, and build semantic datasets.
Agent userAsk questions against approved semantic datasets.
Auditor or governance reviewerReview the governance areas assigned to the account.
Customer Super AdminManage customer settings, users, roles, Audit, and Activity.

This is an example, not a required role design. Use your organisation’s approved separation-of-duties model.

Administrators should periodically:

  1. Review active users and remove access that is no longer needed.
  2. Check custom role permissions.
  3. Review restricted project membership.
  4. Confirm exposure levels for sensitive modules.
  5. Confirm the organisation’s Mask to AI policy.
  6. Review Audit, Activity, and Login Activity for unexpected use.