{"wiki":{"id":44,"slug":"access-management","entity_type":"app","entity_id":"access-management","title":"Access Mgmt - Users","prose_md":"## About\n\nAccess Mgmt – Users is the gatekeeper that verifies who you are and what you’re allowed to do when you interact with Carol’s apps. While Carol’s world is powered by AI agents, human team members still need a secure, controlled way to log in, manage sessions, and move between tools like [[carol-chat]], [[carol-monitor]], or [[admin]]. This app answers a simple question: “Is this person really who they claim to be, and do they have the right to be here?” It handles authentication (proving identity) and authorization (granting permissions) for all *human* users across the ecosystem, keeping a clear separation from the separate [[agent-access]] service that does the same for Carol’s AI agents. Owned by Heimdall ([[agt_038]]), the Head of Security, it sits quietly behind the scenes, making every login fast, safe, and invisible when everything goes right.\n\n## Usage Patterns\n\nYou’ll encounter Access Mgmt – Users every time a person signs into a Carol application. For example, imagine Galadriel ([[agt_013]]), the Product Owner, opens her browser to review feature progress in the [[carol-monitor]]. She’s redirected to the central auth service (`/dev/auth/`), where she enters her credentials. This app validates them, checks her access level, and silently hands her a token that grants access to exactly the tools her role permits—and nothing more. If she later moves to [[carol-chat]] for a quick conversation, the same token is recognized, so she doesn’t re-login. The service also works behind the scenes when scheduled jobs need to confirm a user’s permissions before unleashing more sensitive operations. Because it’s not public, it only serves the internal crew, coordinating with [[user-management]] to keep profiles and roles up to date. That way, Carol’s human collaborators stay connected without ever needing to think about locks and keys.","namesake_json":"{}","profile_pic_path":"avatars/app/access-management.png","source_hash":"8207d1fdc3cdca17c483cdefb51254681764fd70559feb4b1d6a6c5d68cd1c8d","status":"active","last_generated_at":"2026-07-31 20:40:35","created_at":"2026-06-27 03:35:59","updated_at":"2026-07-31 20:40:35"},"facts":{"id":"access-management","name":"Access Mgmt - Users","port":7130,"url":"https://carol.denken-labs.com/dev/auth/","description":"Authentication & authorization","owner":"agt_038","dir_name":"auth","card_group":"user_facing","is_public":0,"access_level":"auth","log_name":"auth","gen_nginx":1,"user_admins":"[]","agent_scope":"confidential","os_user":"carolapps","workers":1,"proxy_read_timeout_s":null,"access_policy":"default","access_policy_humans":"default","named_users":"[]"},"page":{"type":"app","page_class":"main","class_label":"Main page","kind_label":"App","kind_gloss":"","listed":true}}