Skip to main content
Access control in Agent Vault happens at two levels:
  1. Product membership: being added to Agent Vault itself
  2. Access bundle grants: being granted an access bundle, which lets you create sessions with it
Users, groups, and machine identities go through both levels and use the same roles, so this page applies to all three unless it says otherwise.
Access control doesn’t directly apply to the actual agents you run through Agent Vault:
  • A user or machine identity uses their access to create a session with an associated access bundle
  • Agents can only make requests that are allowed by their session’s access bundle
This keeps the user or machine identity directly accountable for what an agent can access.

Product membership

Agent Vault has one member list for your whole organization, instead of one per project. Each member has one of two roles: An admin can use every access bundle without a grant. A member can’t use an access bundle until an admin grants it, and only sees the bundles granted to them. On the Sessions page, members see their own sessions, and admins can switch between All Sessions and My Sessions.
If you’re an organization admin, Infisical adds you to Agent Vault as an admin the first time you open it. You don’t need another admin to add you.

Adding members

You need the Admin role in Agent Vault to add members.
1
In Agent Vault, go to Access Control.
2
Select the Users, Machine Identities, or Groups tab.
3
Select Add Users, Add Machine Identity, or Add Group.
4
Select who to add, and choose Admin or Member in Product Role.
You can only add users who are already in the organization, including users whose invite is still pending. If a user’s invite is pending, they can’t create sessions until they accept it.
You can’t change your own role or remove your own access. Ask an admin if you need to do either.

Access bundle grants

Adding someone to Agent Vault doesn’t automatically give their agents access to any external APIs. They also need a grant on an access bundle, which defines the external APIs their agents can access during a session.
You need the Admin role in Agent Vault to grant access bundles.
Open an access bundle and select Manage Access to grant it to a user, machine identity, or group.

Groups

If you grant an access bundle to a group, every member of that group gets access to it, and each member can independently create sessions.
If someone joins the group, they inherit access to the bundle. If they leave the group, they lose access to the bundle.

When access changes

If someone’s Agent Vault membership or access bundle grants change while their agent is running, the proxy applies the change to the agent’s requests within one poll interval (60 seconds by default). They don’t need to restart the agent. If someone is removed from Agent Vault, Infisical also removes their access bundle grants. If they get added back, they’ll need to be re-granted the same access bundles again before their sessions get credentials.
For more information about what happens when access changes mid-run, check out access changes.