Permissions & Security Model

AVAILABLE

To protect sensitive tenant data and model credentials, Naagmani enforces a strict Least-Privilege Security Sandbox for all plugins.


Permission Scopes #

Plugins must declare all required permissions in their plugin.json manifest. Any attempt to read or mutate unpermitted fields will be blocked by the Gateway kernel.

ScopeDescriptionRisk Level
request:read_bodyRead incoming prompt messages and request arguments.Medium
request:mutate_bodyModify or rewrite prompt messages, temperature, and parameters.High
request:read_headersInspect inbound HTTP request headers.Low
response:read_bodyInspect generated model responses and tool outputs.Medium
response:mutate_bodyModify generated output before it reaches the client.High
vault:read_secretsRequest decrypted project credentials (restricted to certified plugins).Critical
telemetry:emitAppend custom metrics and trace tags to Attempt Telemetry.Low

Secret Isolation #

Plugins never have direct access to provider API keys (e.g. your master OpenAI or Anthropic credentials). The Gateway decrypts vault credentials internally and dispatches requests directly to upstream endpoints.


Next Steps #