Skip to main content

Role-Based Governance

In multi-agent systems, not every agent should have the same permissions. A researcher needs web access but shouldn’t write files. A writer needs file access but shouldn’t make API calls. Role-based governance enforces least privilege per agent.

The Problem

Without role-based governance, you have two options:
  1. One policy for all agents — too permissive for some, too restrictive for others
  2. Per-agent policies — doesn’t scale when you have dozens of agents
Roles solve this by grouping agents with similar responsibilities under shared policies. Define the policy once per role, assign roles to agents.

Role Definitions

TealTiger supports arbitrary role names. Common roles in multi-agent systems:

Configuration

TypeScript

Python


Assigning Roles to Agents

Via observe()

Via Explicit Policy Binding


Tool Allowlists

When a tool call is evaluated, the governance engine checks the caller’s role allowed_tools list:

Pattern Matching

Tool allowlists support glob patterns:

Wildcard

The "*" pattern allows all tools:

Budget Limits Per Role

Each role can have its own cost ceiling:
When an agent exceeds its role’s budget, subsequent requests are denied with reason code ROLE_BUDGET_EXCEEDED.

PII Category Blocking Per Role

Different roles may handle different PII categories:

Default Deny for Unrecognized Roles

When default_deny: true is set, agents with no matching role are blocked:
When default_deny: false (the default), unrecognized roles fall back to the global policy.

Multi-Agent System Example

A complete multi-agent research pipeline with role-based governance:

Audit Integration

When role-based policies are active, every audit event includes the agent’s role:
This provides full visibility into which role boundary was hit and why.

Dashboard Integration

The Agent Matrix panel groups agents by role and shows:
  • Denial rates per role (which roles are hitting limits most?)
  • Cost per role (which roles are most expensive?)
  • Tool usage patterns per role
  • Frozen agents by role
This enables fleet-level role policy tuning from the dashboard.