Security and Identity
This page documents the audited authentication, authorization, tenancy, and security-control surfaces across AlphaSwarm.
Identity architecture
AuthN/AuthZ by surface
| Surface | Identity model | Notes |
|---|---|---|
alphaswarm_ui | Microsoft Entra ID only for hosted customer app; BFF authenticates and proxies to API/control plane. | UI README states Auth0 has been removed and guarded by CI checks. |
alphaswarm_admin | Staff/admin auth integrated with tenant onboarding/admin flows. | Uses Python backend and TypeScript frontends. |
alphaswarm_auth | Provider-agnostic auth service with Entra/GitHub/WebAuthn adapter model, unified RBAC, device hub, software CA. | Owns local platform metadata and short-lived device certificates. |
alphaswarm_platform tenant router | OIDC/JWT verification, tenant/workspace/cell routing, Cell-Bound Authorization validation. | Rejects invalid token state fail-closed in required/permissive modes. |
alphaswarm_worker | OAuth 2.0 device flow plus device registration; optional --require-auth. | Designed for standalone worker node operation. |
alphaswarm_cli | CLI login/setup/control flows; issue audit references YubiKey and connection-error fixes. | Should be aligned with worker/device auth posture. |
alphaswarm_mcp and IDE | MCP/IDE connectivity should rely on platform auth and per-tenant authorization. | Open P0 hardening/go-live issues remain. |
Tenant isolation controls
- Tenant router resolves
tenant_id,workspace_id, organization, user, and tier claims into a deployment cell. - Upstream services receive verified headers such as cell, tenant, workspace, subject, and organization headers after the edge overwrites any client-supplied values.
- RLS is a critical data-plane backstop for tenant/workspace tables.
- Open issues indicate strict-mode RLS rollout is not fully proven and some tenant-scoped tables still lack complete policies.
Security-positive design choices
alphaswarm_ops_consoleuses predeclared argv lists and constrained parameters instead of shell-string execution.- Hosted UI is Entra-only and explicitly separates marketing site, local client, staff admin, and authenticated app responsibilities.
- Tenant router accepts asymmetric JWT algorithms only and fails fast on unusable auth config.
- Device/WebAuthn/CA design supports short-lived mTLS client certificates and hardware-key step-up.
alphaswarm_orchestrationrejects inline secret-bearing keys in portable contracts and keeps secrets as references.- Observability SDK split (
alphaswarm_observe,alphaswarm_observe_js) supports privacy-first telemetry boundaries.
Critical security gaps from open issues
| Priority | Gap | Evidence |
|---|---|---|
| P0 | Some tenant-scoped tables carry workspace_id but lack RLS policies. | alphaswarm#138 |
| P0 | Context-less writers fail closed under tenancy RLS enforcement. | alphaswarm#137 |
| P0 | RLS strict-mode rollout and null-workspace backfill need validation before go-live. | alphaswarm#32 |
| P0 | Agent-ledger RLS DDL must be applied to every target DB before enforcement. | alphaswarm#139 |
| P1 | Bootstrap path does not seed default tenancy rows for fresh create/stamp DB. | alphaswarm#145 |
| P1 | Read-only health collectors under-report under RLS enforcement. | alphaswarm#146 |
| P1 | Episode lesson storage needs PII redaction beyond length cap. | alphaswarm_agents#20 |
Documentation requirements
Security documentation in alphaswarm_docs should include:
- Entra onboarding for customer tenants and staff tenants.
- OIDC/JWT tenant-router configuration and fail-closed modes.
- Device registration, WebAuthn, software CA, and worker/CLI login lifecycle.
- RBAC role/scope matrix by service surface.
- RLS rollout checklist, migration prerequisites, and emergency rollback steps.
- Secret handling policy: document references and stores, never secret values.
- Ops console governance model and future mutation approval gates.