[management] Let usage_viewer read Agent Network access logs (#7750)

usage_viewer saw account-wide usage but only its own request logs, so
the people reviewing cost could not drill into the requests behind it.
The role now also holds Read on agent_network.logs, which makes the
access-log and session endpoints return every caller's rows instead of
self-scoping. Logs can contain captured prompts, so this widens what the
role exposes; policies, guardrails, budgets and settings stay hidden.

Co-authored-by: Misha Bragin <bangvalo@gmail.com>
This commit is contained in:
Nicolas Frati
2026-09-30 23:41:30 +02:00
committed by GitHub
co-authored by Misha Bragin
parent fd1a0203c7
commit 82e5428c2f
3 changed files with 28 additions and 23 deletions
+6 -6
View File
@@ -110,12 +110,12 @@ Two roles delegate Agent Network access without account-admin rights:
read-only users, groups, peers, and account info (needed to build policies).
Nothing else in the account.
- **`usage_viewer`** — the regular User baseline plus read on
`agent_network.usage` (the aggregated usage and cost overview) and read-only
access to the resources the usage filters resolve against: users, groups,
peers, and the provider list (connection config redacted — no upstream URLs
or operator-supplied header values). No policies, and no account-wide
request-level access logs; like any caller, it still reads its own requests
through the self-scoped endpoints below.
`agent_network.usage` (the aggregated usage and cost overview) and
`agent_network.logs` (the account-wide request-level access logs, which can
contain captured prompts), and read-only access to the resources those
filters resolve against: users, groups, peers, and the provider list
(connection config redacted — no upstream URLs or operator-supplied header
values). No policies, guardrails, budgets, or settings.
Every authenticated user, regardless of role, can read the caller-scoped
self-service endpoint `GET /api/agent-network/agent-config` (the endpoint, providers,