- Product membership: being added to Agent Vault itself
- Access bundle grants: being granted an access bundle, which lets you create sessions with it
Access control doesn’t directly apply to the actual agents you run through Agent Vault:
- A user or machine identity uses their access to create a session with an associated access bundle
- Agents can only make requests that are allowed by their session’s access bundle
Product membership
Agent Vault has one member list for your whole organization, instead of one per project. Each member has one of two roles:
An admin can use every access bundle without a grant. A member can’t use an access bundle until an admin grants it, and only sees the bundles granted to them. On the Sessions page, members see their own sessions, and admins can switch between All Sessions and My Sessions.
If you’re an organization admin, Infisical adds you to Agent Vault as an admin the first time you open it. You don’t need another admin to add you.
Adding members
You need the Admin role in Agent Vault to add members.
1
In Agent Vault, go to Access Control.
2
Select the Users, Machine Identities, or Groups tab.
3
Select Add Users, Add Machine Identity, or Add Group.
4
Select who to add, and choose Admin or Member in Product Role.
You can’t change your own role or remove your own access. Ask an admin if you need to do either.
Access bundle grants
Adding someone to Agent Vault doesn’t automatically give their agents access to any external APIs. They also need a grant on an access bundle, which defines the external APIs their agents can access during a session.You need the Admin role in Agent Vault to grant access bundles.
Groups
If you grant an access bundle to a group, every member of that group gets access to it, and each member can independently create sessions.If someone joins the group, they inherit access to the bundle. If they leave the group, they lose access to the bundle.