Multi-tenancy and tiered access in Data
How BullSequana AI isolates Data workspaces and applies viewer, editor, administrator, and pipeline roles.
BullSequana AI provides tenant isolation and team-scoped access throughout Data. In Developer Workspace, each Kubeflow profile maps to an isolated workspace namespace, and the platform creates distinct identities for human access and pipeline execution.
Tenant and team boundaries
A tenant represents one customer or organization. Teams organize departments or working groups inside that tenant. Workspace membership, notebooks, pipelines, artifacts, and service access follow this hierarchy.
Users discover and operate only the resources allowed by their tenant, team, and assigned role. Provider-level administration remains separate from tenant and workspace administration.
Workspace access tiers
BullSequana AI replaces Kubeflow's single collaborator role with four identities in every profile namespace:
| Access tier | Service account | Product behavior |
|---|---|---|
| Viewer | default-viewer | Reads notebooks, pipelines, and logs without changing workspace resources. |
| Editor | default-editor | Creates notebooks and runs pipelines without unrestricted namespace administration. |
| Administrator | default-admin | Manages the workspace namespace and its membership-bound resources. |
| Pipeline runner | pipeline-runner | Executes Argo Workflows independently of any human user's access tier. |
This tiered model gives workspace owners a least-privilege alternative to granting every collaborator the same permissions.
Automatic policy enforcement
The platform generates the required ServiceAccounts and RoleBindings whenever a Kubeflow profile namespace is created. Kyverno policies reconcile the access tiers automatically and also apply them to existing profile namespaces.
Administrators assign users to the appropriate tier; they do not create Kubernetes identities or bindings by hand. The generated resources remain aligned with the profile namespace throughout its lifecycle.
Separate pipeline identity
Pipeline runs use pipeline-runner rather than inheriting the permissions of the person who submitted the run. This separation keeps automated execution stable when team membership changes and prevents a pipeline from receiving administrator access simply because its author has that role.
The same identity is used consistently by the Kubeflow Pipelines and Argo Workflows integration.
What administrators control
Tenant and workspace administrators control:
- which users belong to the tenant and team
- which workspace profile they can access
- whether their role is viewer, editor, or administrator
- which data, secrets, and compute resources the workspace can use
BullSequana AI creates and enforces the corresponding workspace identities and Kubernetes permissions.