Skip to main content

Overview

Akhara uses a hierarchical permission model where access is controlled at two levels:
  1. Organization Level: Global settings, billing, user management, and cross-project visibility
  2. Project Level: Datasets, evaluations, reviews, and project-specific configurations
Permissions cascade down: organization admins have access to all projects, while project-level roles are scoped to specific projects.

Permission Hierarchy

Organization Permissions

Organization Settings

*Members can create projects if enabled in org settings

User Management

Project Permissions

Project Configuration

Data & Evaluation Access

*Requires explicit PHI access grant

Review Queue Access

*Within credentialed scope only

Managing Access

Invite Users to Organization

Add Users to Projects

Bulk Permission Updates

Project Visibility

Control which projects users can see:

Visibility Modes

PHI Access Control

PHI access is controlled separately from general permissions:

Grant PHI Access

PHI Access Policies

Team Management

Create Teams

Organize users into teams for easier permission management:

Team Permissions

When a team is added to a project, all team members inherit the assigned role. Individual overrides can be applied:

Access Requests

Enable self-service access requests for governed onboarding:
Users can then request access:

Best Practices

Least Privilege

Start with Viewer role and escalate only as needed

Use Teams

Group users by function for easier management

Regular Reviews

Audit project membership quarterly

PHI Minimization

Only grant PHI access with documented justification

Role-Based Access Control

Detailed role definitions and permission matrix

Audit Logs

Track all permission changes and access events