Skip to content

docs: document Agent Network Admin and Usage Viewer roles - #1009

Merged
TechHutTV merged 2 commits into
mainfrom
docs/agent-network-user-roles
Oct 1, 2026
Merged

TechHutTV merged 2 commits into
mainfrom
docs/agent-network-user-roles

Conversation

@jnfrati

@jnfrati jnfrati commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Documents the two Agent Network user roles, Usage Viewer.

  • manage/team/user-roles: eight roles, sections for both new roles, an Agent Network permissions table, and a warning that Usage Viewer can read other users' captured prompts. Also notes that neither role can create personal access tokens.
  • agent-network/usage-and-logs: "Who can see what" notes on the index, Access Logs and Usage Overview pages.

Depends on netbirdio/netbird#7750 (Usage Viewer access to account-wide access logs). Merge after it lands.

Summary by CodeRabbit

  • Documentation
    • Clarified which roles can view account-wide usage, access logs, and requests, and that other users can view only their own.
    • Documented that, when prompt collection is enabled, specified roles can view other users’ captured prompts and completions.
    • Added Agent Network Admin and Usage Viewer role permissions, restrictions, and assignment guidance, including that they cannot create personal access tokens.

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 1, 2026 7:03pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 6c9b23f7-a1b7-4b5a-9e01-cc6532037d7c

📥 Commits

Reviewing files that changed from the base of the PR and between 55cc9bf and a7ce0d4.

📒 Files selected for processing (3)
  • src/pages/agent-network/usage-and-logs/access-logs.mdx
  • src/pages/agent-network/usage-and-logs/index.mdx
  • src/pages/agent-network/usage-and-logs/usage-overview.mdx
🚧 Files skipped from review as they are similar to previous changes (3)
  • src/pages/agent-network/usage-and-logs/access-logs.mdx
  • src/pages/agent-network/usage-and-logs/usage-overview.mdx
  • src/pages/agent-network/usage-and-logs/index.mdx

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The documentation describes Agent Network Admin and Usage Viewer permissions. It also states which roles can view account-wide usage, requests, and captured prompts when prompt collection is enabled.

Changes

Agent Network permissions and visibility

Layer / File(s) Summary
Document Agent Network roles
src/pages/manage/team/user-roles.mdx
Adds permissions, restrictions, prompt visibility details, and role-assignment guidance for Agent Network Admin and Usage Viewer.
Document usage and log visibility
src/pages/agent-network/usage-and-logs/*
Describes which roles can view account-wide usage and requests, and which users can view only their own. Notes that prompt collection exposes captured prompts and completions to the listed roles.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to a7ce0

The documentation consistently explains account-wide visibility and captured-prompt access. No blocking issue was identified; retain the planned merge ordering after the Usage Viewer backend change and run normal documentation checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 55cc9

The documentation explains who can view account-wide activity and captured prompts, without changing access controls in this PR. Its accuracy depends on a separate role rollout that could not be verified here.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — If the documented grants are enforced, a holder of a listed account-wide role can see other callers’ retained access logs within the account, including captured prompts when enabled. The documented fallback limits callers without that grant to their own requests.

Trust Boundaries and Controls

  • observed — The documented boundary is an account-wide grant rather than unrestricted access for every signed-in user. The available endpoint descriptions do not identify which role claims supply that grant, so they cannot verify the new role-to-grant assertions.

Hardening Proposals

  • proposed — Before publishing the role guidance, verify that the dependent rollout maps each named role to the documented usage and access-log grants, prompt visibility, provider-field redaction, and token-creation restrictions.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main documentation change: adding the Agent Network Admin and Usage Viewer roles.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reads the roles with care,
And finds who sees each prompt laid bare.
Usage logs now show the view,
And access rules are clearer too.
The rabbit hops through docs anew.

Comment @coderabbitai help to get the list of available commands.

@jnfrati
jnfrati force-pushed the docs/agent-network-user-roles branch from a7ce0d4 to 90912a4 Compare October 1, 2026 18:59
@TechHutTV
TechHutTV merged commit 8cff42c into main Oct 1, 2026
5 checks passed
@TechHutTV
TechHutTV deleted the docs/agent-network-user-roles branch October 1, 2026 19:06

This branch was successfully deployed

1 active deployment
Preview — 90912a4d Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants