Skip to main content
Operator access controls the people and automation that manage Tilde: who can sign in, and what each of them can see and change. It is part of Tilde Cloud and Tilde Enterprise. For what agents and end users can do, see IAM.
Tilde OSS has no operator roles, management API keys, or OIDC configuration. See Editions.

Sign in with your identity provider

Tilde delegates operator sign-in to your OIDC identity provider, so your existing sign-in policies, such as multi-factor authentication, apply. Tilde has no local password accounts. We provide SAML support for individual clients on request. Browser sign-in uses the authorization code flow with PKCE. An operator session lasts eight hours, and signing out revokes it. Tilde stores only a hash of each session.

Groups

A group is an audience for roles. Tilde has four kinds:

Operator roles

A role is a named set of actions on a resource, or on every resource of a kind. A person, group, or API key can hold any number of roles, and their actions add up. Actions never imply each other, so a role states everything it gives.

Agent roles

Every agent has three roles: The person who creates an agent becomes its editor and deployer. An agent you cannot view is reported as not found. The editor role holds a set of fine-grained actions. A custom role can grant one part of an agent without the rest.

Connection, tool server, and skill group roles

Connections, Tilde tool servers, and skill groups each have their own roles: The person who creates one becomes its editor. To give one to an agent, you need the matching action on the agent and view on the connection, tool server, or group.

Installation-wide roles

Administrators can grant a role on every resource of a kind, such as every agent or every connection. It covers resources that exist now and those created later.

Share a resource

Select Share on an agent, connection, tool server, or skill group. You can grant only roles within your reach:
  • Editors can hand out reader and editor.
  • Deployers can hand out reader and deployer.
  • Administrators can hand out any role.
To open an agent to every operator, select Anyone can view. This grants the reader role to the all-users group.

Management API keys

Management API keys authenticate CI pipelines and other automation to the management API. A key holds roles exactly as a person does. Create and revoke keys under API keys. Tilde shows each key once, and stores only its hash and a display prefix. Revocation takes effect across the platform within seconds. A key has these limits:
  • It joins no groups, and is never an administrator.
  • It cannot manage access, users, groups, or other keys.
  • Its creator can give it only roles within their own reach.
  • It owns nothing it creates. To create an agent, connection, or tool server, it needs edit on every resource of that kind.
  • It cannot open browser sessions. Agent runtimes never receive management keys.
Non-administrators can list and revoke only their own keys.