Control Tower v0.2.1

People and roles

Everyone who signs in to the console has a role:

RoleCan
AdminChange anything: providers, models, keys, gates, zones, alerts, exports, guardrails, and people
ApproverSee everything, and approve or deny held calls in the Tower (and from Slack or email links). Ending an approval window early is for admins
ViewerSee everything: the map, Flights, the Ledger, the Tower, every setting. Change nothing
MemberSee only their teams: their agents, calls, held calls, spend and map. What they may change there, their team memberships decide (Enterprise)

With Enterprise, team and organisation memberships add rights to anyone: team admins manage their team's keys, budgets and people, and team members decide its held calls.

The person who sets up Control Tower is its first admin. The server enforces roles: an approver or viewer who tries to change something gets 403 forbidden. Their console says what they can do, and hides the buttons for what they can't. Both can still change their own password.

The admin key always acts as an admin.

Every change anyone makes, and every attempt their role refuses, is recorded in the audit log. Only admins can read it.

Single sign-on

People can also sign in through your identity provider, with their role set by their groups there, and passwords can be turned off. See Single sign-on.

People: an admin, someone with a one-time password, and people provisioned by the identity provider

Adding people

People (admins only) → enter an email and a role → Add person. Control Tower shows a one-time password, only once. Share it with them however you share secrets.

Adding an approver on the People page

The one-time password, shown once

When they sign in with it, the only thing they can do is choose their own password (10 characters or more). After that, the one-time password no longer works.

  • Change a role in the list. It takes effect at once: the person's current sessions end, and they sign in again with the new role.
  • Reset password gives the person a new one-time password and ends their sessions. Use it when someone forgets theirs.
  • Remove takes their access away. You can't remove yourself, and someone always stays an admin: the last admin can't be removed or made an approver or viewer.

Your own password

The key button next to your name in the sidebar changes your password. Your other sessions end; the one you're using stays signed in.

If the only admin loses their password

If CT_ADMIN_KEY is set, use it to give the admin a new one-time password:

curl -s -H "Authorization: Bearer $CT_ADMIN_KEY" https://controltower.example.com/admin/api/users
curl -s -X PATCH -H "Authorization: Bearer $CT_ADMIN_KEY" -H "content-type: application/json" -d '{"reset_password": true}' https://controltower.example.com/admin/api/users/<id>

With CT_ADMIN_KEY set, you can also sign in as admin with the key itself.

API

MethodPath
GET, POST/admin/api/usersList people (admins only); add one ({email, role}). The answer includes the one-time password, once
PATCH, DELETE/admin/api/users/:idChange the role ({role}) or reset the password ({reset_password: true}), which returns a new one-time password; remove
POST/admin/api/me/passwordChange your own: {current, password}

GET /admin/api/me includes your role.