Skip to content

Help centre

Access, roles and the audit trail in Marella

How to scope who can see and ask what, and what to test on permissions, decision records and the evidence gaps that remain before you deploy.

The access model

Access is set at four levels: organisation, department, role and agent scope.

Departments group people and documents around a team or a workflow, and your evaluation should check what a department member can actually retrieve rather than what the setting implies. Roles decide what someone can do: ask questions, curate the knowledge network, configure agents or administer the organisation. Agent scope selects the document sets a configured agent may draw on, so test both the material an agent should reach and the material it should not.

These controls support information boundaries, but they do not prove that a connector carries the source system’s permissions across, or that one organisation’s data stays separate from another’s. Test both during deployment.

Decision traces and the audit log

Marella exposes two different records. Decision traces can record what an agent did and why, including which citations and tools it used. Security-event records cover organisation events such as invitations and role changes. Which events are covered, how long they’re kept, who can read them and how they’re exported all depend on the deployment, so get those documented during procurement.

Setting it up well

  1. Mirror your org chart first and refine later. Familiar boundaries beat clever ones.
  2. Where the work is sensitive, scope agents tighter than departments. A contracts agent has no business reaching HR policies.
  3. Bring governance reviewers in early, and agree how they’ll inspect the relevant records while the evaluation is still running.