Andy.Rbac.Cli
2026.7.21-rc.92
dotnet tool install --global Andy.Rbac.Cli --version 2026.7.21-rc.92
dotnet new tool-manifest
dotnet tool install --local Andy.Rbac.Cli --version 2026.7.21-rc.92
#tool dotnet:?package=Andy.Rbac.Cli&version=2026.7.21-rc.92&prerelease
nuke :add-package Andy.Rbac.Cli --version 2026.7.21-rc.92
Andy RBAC
Role-Based Access Control (RBAC) system for Andy applications.
ALPHA RELEASE WARNING
This software is in ALPHA stage. NO GUARANTEES are made about its functionality, stability, or safety.
CRITICAL WARNINGS:
- Permission management is NOT FULLY TESTED and may have security vulnerabilities
- Authorization decisions may be INCORRECT or INCONSISTENT
- DO NOT USE in production environments
- DO NOT USE to protect sensitive resources or data
- The authors assume NO RESPONSIBILITY for unauthorized access or security breaches
USE AT YOUR OWN RISK
Features
- Role-Based Access Control - Hierarchical roles with permission inheritance
- Fine-Grained Permissions - Resource-level and instance-level permissions
- Policies - Execution-time risk profiles (
read-only,high-risk,sandboxed,no-prod,draft-only,write-branch) governing agent actions, gates, and retention - Multi-Application Support - Single RBAC server for multiple applications
- Team Management - Organize users into teams with shared permissions
- gRPC and REST APIs - High-performance permission checking
- ASP.NET Core Integration - Authorization handlers and policy providers
- Caching - In-memory caching for fast permission lookups
- MCP Support - Model Context Protocol tools for AI assistants
- CLI -
andy-rbacfor managing applications, roles, teams, users, and policies
Quick Start
Prerequisites
- .NET 8.0 SDK
- Docker Desktop (for PostgreSQL)
Local Development
# Start PostgreSQL
docker-compose up -d
# Run the API server
cd src/Andy.Rbac.Api
dotnet run
API runs at: https://localhost:5003
Project Structure
src/
Andy.Rbac/ Core library (models, abstractions, authorization)
Andy.Rbac.Api/ REST and gRPC API server
Andy.Rbac.Client/ HTTP/gRPC client library
Andy.Rbac.Infrastructure/ EF Core, repositories
Andy.Rbac.Web/ Admin UI (Blazor)
Andy.Rbac.Cli/ Command-line interface
tests/
Andy.Rbac.Tests/ Core library tests
Andy.Rbac.Api.Tests/ API integration tests
Andy.Rbac.Client.Tests/ Client library tests
NuGet Packages
| Package | Description |
|---|---|
| Andy.Rbac | Core RBAC library with models, abstractions, and authorization |
| Andy.Rbac.Client | HTTP and gRPC client for the RBAC API |
| Andy.Rbac.Cli | Command-line tool for managing RBAC resources |
Install the client library to integrate RBAC into your application:
dotnet add package Andy.Rbac.Client
Usage
// Add to Program.cs
builder.Services.AddRbacClient(options =>
{
options.BaseUrl = "https://rbac-api.example.com";
options.ApplicationCode = "my-app";
});
// Use in controllers
[RequirePermission("document:read")]
public async Task<IActionResult> GetDocument(string id) { }
[RequireAnyPermission("document:write", "document:admin")]
public async Task<IActionResult> UpdateDocument(string id) { }
[RequireRole("admin")]
public async Task<IActionResult> DeleteDocument(string id) { }
Permission Format
Permissions follow the format: {app-code}:{resource-type}:{action}
Examples:
andy-docs:document:readandy-docs:document:writeandy-docs:folder:create
API Endpoints
Permission Checking
POST /api/check- Check single permissionPOST /api/check/any- Check if a user has any of the permissionsGET /api/check/permissions/{subjectId}- Get all permissions for a userGET /api/check/roles/{subjectId}- Get all roles for a user
Management
/api/applications- Application CRUD/api/roles- Role management/api/subjects- User/subject management/api/teams- Team management/api/policies- Policy catalog (Epic V — see docs/policies.md)
Policies
A policy is a named risk profile that downstream services (andy-tasks, andy-docs, Conductor) consume to decide auto-gating, retention, and action enforcement. Six stock policies ship pre-seeded (read-only, write-branch, sandboxed, no-prod, high-risk, draft-only); tenants may register additional policies via POST /api/policies.
See docs/policies.md for the full catalog, rule key reference, event taxonomy, and FAQ. The design rationale is captured in ADR 0001 — Policies as first-class catalog rows.
CLI
The andy-rbac CLI (src/Andy.Rbac.Cli) wraps the REST API for terminal-based admin and agent automation:
# Applications, roles, teams, users
andy-rbac app list
andy-rbac role list --application andy-tasks
andy-rbac team list
andy-rbac user search jane
# Policies (Epic V)
andy-rbac policy list # six stock policies + tenant overrides
andy-rbac policy list --criticality High # filter by criticality
andy-rbac policy get high-risk # full rule body for a policy
# Permission checks
andy-rbac check permission user-123 andy-tasks:goal:read
# Output formats: --output table (default) | json | csv
Global flags: --api-url / -u (env ANDY_RBAC_URL), --api-key / -k (env ANDY_RBAC_API_KEY), --output / -o.
MCP Tools
The andy-rbac API exposes MCP tools for AI assistants. Read-only tools cover permission checks and the Policy catalog; write tools cover application/role/team/user management.
# Permission checks
CheckPermission, GetUserPermissions, GetUserRoles
# Catalog reads
ListApplications, GetApplication, ListRoles, ListTeams, SearchUsers, GetUser
ListPolicies, GetPolicy
# Mutations (admin-only paths)
CreateApplication, CreateRole, AssignRoleToUser, RevokeRoleFromUser,
CreateTeam, AddUserToTeam, AssignRoleToTeam, CreateUser
Policy mutations (POST / PUT / DELETE) are intentionally not surfaced via MCP — they stay on the REST surface so admin authorization paths don't move through tool calls.
Testing
# Run all tests
dotnet test
# Run with coverage
dotnet test --settings coverlet.runsettings --collect:"XPlat Code Coverage"
Technology Stack
- Framework: ASP.NET Core 8.0
- Database: PostgreSQL with EF Core
- APIs: REST + gRPC
- Caching: IMemoryCache
- Testing: xUnit, FluentAssertions, Moq
License
Apache 2.0 - see the LICENSE file for details.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 2026.7.21-rc.92 | 88 | 7/21/2026 |
| 2026.7.21-rc.90 | 65 | 7/21/2026 |
| 2026.7.2-rc.88 | 76 | 7/2/2026 |
| 2026.7.2-rc.87 | 77 | 7/2/2026 |
| 2026.6.8-rc.85 | 79 | 6/8/2026 |
| 2026.6.5-rc.83 | 70 | 6/5/2026 |
| 2026.5.22-rc.80 | 86 | 5/22/2026 |
| 2026.5.18-rc.79 | 75 | 5/18/2026 |
| 2026.5.18-rc.78 | 76 | 5/18/2026 |
| 2026.5.18-rc.77 | 67 | 5/18/2026 |
| 2026.5.17-rc.76 | 87 | 5/17/2026 |
| 2026.5.17-rc.74 | 63 | 5/17/2026 |
| 2026.5.17-rc.73 | 67 | 5/17/2026 |
| 2026.5.17-rc.72 | 62 | 5/17/2026 |
| 2026.5.17-rc.71 | 73 | 5/17/2026 |
| 2026.5.17-rc.69 | 78 | 5/17/2026 |
| 2026.5.17-rc.67 | 67 | 5/17/2026 |
| 2026.5.17-rc.66 | 68 | 5/17/2026 |
| 2026.5.17-rc.64 | 78 | 5/17/2026 |
| 2026.5.17-rc.63 | 67 | 5/17/2026 |