Multi-tenancy and tiered access in Data

How BullSequana AI isolates Data workspaces and applies viewer, editor, administrator, and pipeline roles.

Agentic Friendly

BullSequana AI provides tenant isolation and team-scoped access throughout Data. In Developer Workspace, each Kubeflow profile maps to an isolated workspace namespace, and the platform creates distinct identities for human access and pipeline execution.

Tenant and team boundaries

A tenant represents one customer or organization. Teams organize departments or working groups inside that tenant. Workspace membership, notebooks, pipelines, artifacts, and service access follow this hierarchy.

Users discover and operate only the resources allowed by their tenant, team, and assigned role. Provider-level administration remains separate from tenant and workspace administration.

Workspace access tiers

BullSequana AI replaces Kubeflow's single collaborator role with four identities in every profile namespace:

Access tierService accountProduct behavior
Viewerdefault-viewerReads notebooks, pipelines, and logs without changing workspace resources.
Editordefault-editorCreates notebooks and runs pipelines without unrestricted namespace administration.
Administratordefault-adminManages the workspace namespace and its membership-bound resources.
Pipeline runnerpipeline-runnerExecutes Argo Workflows independently of any human user's access tier.

This tiered model gives workspace owners a least-privilege alternative to granting every collaborator the same permissions.

Automatic policy enforcement

The platform generates the required ServiceAccounts and RoleBindings whenever a Kubeflow profile namespace is created. Kyverno policies reconcile the access tiers automatically and also apply them to existing profile namespaces.

Administrators assign users to the appropriate tier; they do not create Kubernetes identities or bindings by hand. The generated resources remain aligned with the profile namespace throughout its lifecycle.

Separate pipeline identity

Pipeline runs use pipeline-runner rather than inheriting the permissions of the person who submitted the run. This separation keeps automated execution stable when team membership changes and prevents a pipeline from receiving administrator access simply because its author has that role.

The same identity is used consistently by the Kubeflow Pipelines and Argo Workflows integration.

What administrators control

Tenant and workspace administrators control:

  • which users belong to the tenant and team
  • which workspace profile they can access
  • whether their role is viewer, editor, or administrator
  • which data, secrets, and compute resources the workspace can use

BullSequana AI creates and enforces the corresponding workspace identities and Kubernetes permissions.

On this page