cognee-permissions
Use when working with cognee's permission system — understanding or changing how users, roles, and tenants get access to datasets, how ACL grants work, where permissions are enforced in add/cognify/search/delete, and how the grant records surface in the memory-provenance view.
Profil de l’actif
Recherche et travail de connaissance
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scénario
RAG and knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
Adéquation Agent
Claude Code + CLI + Codex
Compatible avec Codex, Claude Code, Cursor, CLI ou des Agents personnalisés.
Installer
Prêt
npx skills add topoteretes/cognee --skill cognee-permissions
Maintenance
À jour
Mis à jour aujourd’hui
Risque
Revue nécessaire
Permission surface may require sandboxing
Qualité GitHub
30K
92/100 Qualité · 80/100 Confiance
Tags de couverture
Notes de revue
Permission surface may require sandboxing · SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
Carte d’adoption Agent
Confiance, audit et préparation à l’installation en un coup d’œil
Ces scores combinent les métadonnées publiques du dépôt, les signaux de revue OpenAgentSkill, la fraîcheur de maintenance et la préparation à l’installation. Ils servent à présélectionner et ne remplacent pas la revue humaine.
Qualité
ExcellentHigh-confidence pick with strong adoption and healthy maintenance signals.
Confiance
Sandbox uniquementCandidate utile avec des signaux de confiance incomplets ou mixtes. Gardez-la dans un espace isolé jusqu’à ce que la boucle de résultats confirme son adéquation.
Audit
Revue nécessaireRevue lisible par machine de la préparation à l’installation, des métadonnées de sécurité, de la maintenance et du risque d’adoption.
Trust Score OpenAgentSkill v5
Revue humaine avant installation
Exécutez uniquement dans un sandbox et comparez les alternatives proches avant usage réel.
Stars
30K stars GitHub
Activité du dépôt
30K stars et 3.0K forks
Maintenance
Mis à jour aujourd’hui
Licence
Apache-2.0
Installer
npx skills add topoteretes/cognee --skill cognee-permissions
Sécurité d’installation
Chemin d’installation standard de package ou runtime
Surface de permissions
filesystem or document access, network or browser access
Résultats Agent
Pas encore de données de résultats Agent
Documentation
Usable metadata, review docs
Résumé des risques
Revoir avant production
- SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
- Quality score needs review
- Permission surface needs review: filesystem or document access, network or browser access
- Permission surface: filesystem or document access, network or browser access
Préparation à l’installation
Chemin d’installation disponible
- Le chemin d’installation est disponible
- La preuve du dépôt est disponible
- La licence est déclarée
- Pas encore de preuve de résultat Agent-Proven
Métadonnées lisibles par Agent
Données de décision lisibles par machine pour ce skill.
Utilisez ce bloc ou le JSON intégré pour décider si un Agent doit installer ce skill, choisir une alternative ou demander d’abord une revue humaine.
Tâches adaptées
- workflows Database and SQL
- Équipes Claude Code
- Équipes qui valorisent les signaux d’adoption GitHub
- Understand table relationships
Agents adaptés
Décision d’installation
- Commande
- npx skills add topoteretes/cognee --skill cognee-permissions
- Politique
- Revoir
- Revue humaine
- Oui
Confiance et risque
- Confiance
- 72/100
- Audit
- 87/100
- Niveau de risque
- Revue nécessaire
Boucle de résultat
- Endpoint
- /api/agent/outcome
- ID d’événement
- resolve
- Résultats
- 5
Commande d’installation
npx skills add topoteretes/cognee --skill cognee-permissionsNe pas utiliser quand
- Équipes qui nécessitent un SLA soutenu par le fournisseur
- production agents without a repository review
- SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
- No OpenAgentSkill engagement data yet
- Indices de permissions à haut risque : Secrets or environment access
Skill alternatif
Last30days Skill
53.5K Stars
npx skills add mvanhorn/last30days-skill -g
Skill alternatif
Academic Research Skills
38.4K Stars
npx skills add Imbad0202/academic-research-skills
Skill alternatif
GPT Researcher
28.0K Stars
npx skills add assafelovic/gpt-researcher
Skill alternatif
DeepResearch
19.8K Stars
npx skills add Alibaba-NLP/DeepResearch
Sécurité Agent v2
55/100 · Revoir avant installation
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
Moyen
Accès réseau
La skill récupère probablement des pages distantes, API, dépôts ou services externes.
Moyen
Accès au système de fichiers
La skill peut lire ou écrire des fichiers de projet, documents, artefacts générés ou l’état local de l’espace de travail.
Élevé
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Moyen
Accès à la base de données
La skill peut inspecter des schémas, interroger des bases de données ou travailler avec des stockages persistants.
- Indices de permissions à haut risque : Secrets or environment access
- Permission surface may require sandboxing
Cibles d’installation
Installer ce skill dans votre workflow Agent
Utilisez le point de terminaison public pour récupérer la commande, la checklist, les prompts et les liens canoniques.
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install topoteretes-cognee-permissionsPlan de résolution Agent
Laissez un Agent vérifier la pertinence avant l’installation.
L’API Resolve renvoie la skill sélectionnée, des alternatives, la politique de sécurité, les notes d’audit, la cible d’installation et un prompt prêt à l’emploi.
Ouvrir JSON
/api/agent/resolve?task=Use%20cognee-permissions%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Texte Resolve
/api/agent/resolve?task=Use%20cognee-permissions%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Relais d’installation
/api/skills/topoteretes-cognee-permissions/install
L’Agent doit vérifier
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Copier le prompt
Task: Use cognee-permissions in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20cognee-permissions%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/topoteretes-cognee-permissions/install
Install command: npx skills add topoteretes/cognee --skill cognee-permissions
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Relais Agent
Donnez à l’Agent le chemin d’installation, pas un autre annuaire.
Utilisez le point de terminaison public pour récupérer la commande, la checklist, les prompts et les liens canoniques.
Relais d’installation
/api/skills/topoteretes-cognee-permissions/install
Format texte LLM
/api/skills/topoteretes-cognee-permissions/install?format=text
Trouver des alternatives
/api/skills/search?q=cognee-permissions&limit=3
Prompt Agent
Use cognee-permissions for this task. Review https://www.openagentskill.com/api/skills/topoteretes-cognee-permissions/install, then install with: npx skills add topoteretes/cognee --skill cognee-permissionsMétadonnées Registry
Profil lisible par Agent pour la sélection automatique de skills.
L’API Registry fournit les signaux de décision, confiance, audit, cas d’usage et installation sans analyser l’interface.
Manifest
/api/registry/manifest/topoteretes-cognee-permissions
Texte LLM
/api/registry/manifest/topoteretes-cognee-permissions?format=text
Alias d’installation
/api/registry/install/topoteretes-cognee-permissions
Recommander
/api/registry/recommend?task=Use%20cognee-permissions%20in%20an%20agent%20workflow&limit=3
Adéquation Agent
Database and SQL
Tags de cas d’usage
Plateformes
Claude Code
Rapport d’audit
Revue nécessaire · 87/100
Revue lisible par machine de la préparation à l’installation, des métadonnées de sécurité, de la maintenance et du risque d’adoption.
Panneau de décision Agent
Choix principal pour Database and SQL
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Rôle dans la pile
Choix principal
Pertinence principale
Database and SQL
Libellé de confiance
Prêt pour la production
Chemin d’installation
Commande prête
À utiliser lorsque
- workflows Database and SQL
- Équipes Claude Code
- Équipes qui valorisent les signaux d’adoption GitHub
Preuves
- 30,192 stars GitHub
- recent repository activity
- install command or GitHub repo available
- profil qualité 92/100
revoir d’abord
- SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
- No OpenAgentSkill engagement data yet
Chemin d’implémentation
- 1Installez-le dans un Agent en sandbox et exécutez une tâche de Database and SQL de bout en bout.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Profil de confiance
Sandbox uniquement
Candidate utile avec des signaux de confiance incomplets ou mixtes. Gardez-la dans un espace isolé jusqu’à ce que la boucle de résultats confirme son adéquation.
Adoption GitHub
Validé30K stars GitHub
Activité stars/forks
Validé30K stars et 3.0K forks; l’activité des issues n’est pas disponible dans les métadonnées actuelles
Maintenance récente
ValidéMis à jour aujourd’hui
Clarté de licence
ValidéApache-2.0
Signaux positifs
- Revue IA approuvée
- Le chemin d’installation est disponible
- La preuve du dépôt est disponible
- Dépôt maintenu récemment
- Large GitHub adoption signal
- La commande d’installation ne présente aucun motif de haut risque évident
- La boucle de résultats est prête mais nécessite la première exécution réelle de l’Agent
Réviser avant installation
- SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
- Quality score needs review
- Permission surface needs review: filesystem or document access, network or browser access
- Permission surface: filesystem or document access, network or browser access
- Pas encore de rapports de résultats Agent réels
- Une revue humaine est requise avant une installation sans surveillance
Action recommandée
Exécutez uniquement dans un sandbox et comparez les alternatives proches avant usage réel.
Profil qualité
Excellent candidat pour les workflows Agent
High-confidence pick with strong adoption and healthy maintenance signals.
Adéquation au workflow
Utilisez cette skill dans ces scénarios
Work with data stores
Database and SQL
I need my agent to inspect database schemas, write SQL, and explain query results.
Search private knowledge
RAG and knowledge
I need my agent to build a RAG workflow over documents and retrieve reliable context.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Adéquation au workflow
Ajouter à un workflow complet
Ingest, retrieve, and cite
RAG knowledge base
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Find, compare, and synthesize
Research report agent
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Liste d’alternatives
Comparer avant installation
Similar skills that may fit this task.
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
Academic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
GPT Researcher
Run autonomous deep research over web and local sources
DeepResearch
Tongyi Deep Research, the Leading Open-source Deep Research Agent
Vue d’ensemble
--- name: cognee-permissions description: Use when working with cognee's permission system — understanding or changing how users, roles, and tenants get access to datasets, how ACL grants work, where permissions are enforced in add/cognify/search/delete, and how the grant records surface in the memory-provenance view. ---
# The cognee permission system
## The master switch
`ENABLE_BACKEND_ACCESS_CONTROL` decides whether any of this runs:
- `true` (default): multi-tenant mode. Every API call requires auth, every dataset operation is permission-checked, and each user+dataset pair gets isolated graph/vector/relational databases (tracked in the `DatasetDatabase` model, supported backends: Kuzu, LanceDB, SQLite, Postgres). - `false`: single-user mode. Permission checks short-circuit to allowed, there is no per-dataset isolation, and **every user's operations resolve to the same shared databases and datasets**. Authentication is a separate knob: `REQUIRE_AUTHENTICATION`. Unset, it inherits this switch (so turning access control off also turns auth off) — but if `REQUIRE_AUTHENTICATION=true` is set, endpoints still demand a login; authenticated users are identified but *not isolated*, all pointing at the same data. The reverse misconfiguration (`REQUIRE_AUTHENTICATION=false` with access control on) is ignored: auth is forced on with a warning, because multi-tenant isolation is meaningless without identity (`get_authenticated_user.py`).
## The core model: principals, permissions, ACL grants
Everything reduces to one relation — **a grant**: *principal* × *permission* × *dataset*, stored as one `ACL` row (`modules/users/models/ACL.py`).
- **Principal** (`Principal.py`) is polymorphic: `User`, `Role`, and `Tenant` all inherit from it. Any of the three can hold a grant, which is how role-wide and tenant-wide access work — one ACL row covers every member. - **Permission** (`Permission.py`) is one of exactly four names, defined in `permissions/permission_types.py`: `read`, `write`, `delete`, `share`. `share` is the meta-permission: it gates granting/revoking access for others. - **Membership** is separate from grants: `UserRole` and `UserTenant` link users into roles/tenants. A user's effective access is the union of their own grants and the grants of every role/tenant they belong to.
## How grants come into existence
1. **Dataset creation** (`modules/data/methods/create_authorized_dataset.py`): the creating user is granted **all four permissions** on the new dataset. If the user has a `parent_user_id` (sub-users/agent identities), the parent is auto-granted all four as well — parents always see their children's datasets. 2. **Explicit sharing** (`permissions/methods/ authorized_give_permission_on_datasets.py`): the caller must hold `share` on the target datasets, then any principal (user, role, or tenant) can be granted any permission. Revocation mirrors this (`authorized_revoke_permission_on_datasets.py`). 3. **Capabilities — tenant-scoped grants of actions, not data** (landing via PR #4302, currently in review): a new `principal_capabilities` table, keyed on `(principal, tenant, capability)`. Where an ACL row grants access to *a dataset*, a capability grants *an action inside a tenant* — the first one being `manage_users`. The catalog of capability names is code (`CAPABILITY_TYPES` in `permission_types.py`), not a database table, "because the code is what gives each name meaning"; only the assignment of a capability to a principal is data. `tenant_id` is stored on every row because a user can belong to multiple tenants: it pins each grant to the user's membership in one specific tenant, so holding a capability in one tenant never carries over to the same user's other tenants. Resolution (`get_effective_capabilities(user, tenant)`) returns the union of what the tenant grants all of its members, what the user's roles in that tenant grant, and what the user was granted personally — there is no deny in the model, resolution is gated on actual tenant membership, and the tenant owner short-circuits as holding every capability. Grant/revoke endpoints ride the permissions router.
## Where permissions are enforced
The single chokepoint for dataset resolution is `get_authorized_existing_datasets(datasets, permission, user)` — every entrypoint resolves names/IDs through it with the permission it needs:
| Operation | Required permission | Enforcement path | |---|---|---| | `add` / `cognify` / `remember` | `write` | dataset resolution before the pipeline runs | | `search` / `recall` / visualize | `read` | dataset resolution; retrieval is restricted to documents of readable datasets | | `delete` / prune of a dataset | `delete` | `datasets.py` resolves with `"delete"` | | grant/revoke for others | `share` | `authorized_give/revoke_permission_on_datasets` |
Two behaviors worth knowing:
- **Denied reads return empty results, not 403.** A search against a dataset you cannot read yields `[]` — deliberate, to avoid leaking which datasets exist. When debugging "search returns nothing", check grants before checking the graph.
## Roles, tenants, and who may manage them
- **User management** (listing tenant users, assigning/removing roles, adding/removing users) is allowed for the **tenant owner** always, and today for members of roles named in `USER_MANAGEMENT_ALLOWED_ROLE_NAMES` (currently `{"admin"}`, `permissions/permission_types.py`). That name-matching is a known footgun — any customer group that happens to be called "admin" gets user management — and PR #4302 replaces it: the check becomes "does the requester hold the `manage_users` capability in this tenant" (owner always passes), with the role-name match kept only as a deprecated fallback so tenants upgrading from the old check don't lose user management until their `admin` role is granted the capability. - **Role visibility**: members of a role can see the role itself and their co-members; anyone with user-management permission sees all (`tenants/methods/get_users_in_role.py`). Lookups are tenant-scoped — a role id from another tenant cannot be used to read that tenant's members.
## The grant records in memory provenance (the new grant view)
`api/v1/visualize/memory_provenance.py` surfaces the ACL grants as first-class graph data. Each grant becomes an `AclGrantRecord`:
```python {"principal_id": ..., "principal_kind": "user" | "role" | "tenant", "permission": ...} ```
and is rendered into the provenance graph as an edge from the principal node to the dataset, with the permission mapped to a relation name (`_ACL_EDGE_RELATIONS`):
| permission | provenance edge | |---|---| | read | `reads` | | write | `writes` | | delete | `can_delete` | | share | `can_share` |
Grants are rendered (never dropped) even when the principal is unknown, because "an ACL row exists because someone granted it". The view is exposed through the schema router (`get_schema_router.py`): `visualize_memory_provenance` (HTML) and `get_memory_provenance_payload` (JSON) — this is where you *see* the permission state of a memory rather than query it.
## HTTP API surface (`api/v1/permissions/routers/get_permissions_router.py`)
| Endpoint | What it does | |---|---| | `POST /permissions/datasets/{principal_id}` | grant a permission on datasets to a principal (requires `share`) | | `DELETE /permissions/datasets/{principal_id}` | revoke a permission | | `POST /permissions/roles` · `DELETE /permissions/roles/{role_id}` | create/delete a role | | `POST/DELETE /permissions/users/{user_id}/roles` | add/remove a user to/from a role | | `POST /permissions/users/{user_id}/tenants` | add a user to a tenant | | `GET /permissions/tenants/{tenant_id}/roles/{role_id}/users` | members of a role (self-visible to members) | | `GET /permissions/tenants/{tenant_id}/roles/users/{user_id}` | a user's roles | | `GET /permissions/tenants/{tenant_id}/users` | users in a tenant | | `GET /permissions/tenants/me` | the caller's tenants |
## Key files map
- Models: `cognee/modules/users/models/` — `ACL`, `Principal`, `Permission`, `Role`, `Tenant`, `UserRole`, `UserTenant`, `DatasetDatabase` (and `PrincipalCapability` once #4302 lands) - Methods: `cognee/modules/users/permissions/methods/` — grant/revoke, checks, dataset resolution, document filtering - Enforcement chokepoint: `cognee/modules/data/methods/` (`get_authorized_existing_datasets`, `create_authorized_dataset`) - Grant provenance view: `cognee/api/v1/visualize/memory_provenance.py` - HTTP API: `cognee/api/v1/permissions/routers/get_permissions_router.py`
Détails techniques
- Version
- 1.0.0
- Licence
- Apache-2.0
- Dernière mise à jour
- 23 août 2026
- Publié
- 23 août 2026
Instantané de décision
Choix principal
30,192 stars GitHub
Audit
Revue d’installation
Revue d’installation et d’adoption
- Sécurité
- 78/100
- Maintenance
- 100/100
- Installer
- 92/100
Preuves validées par Agent
Preuves validées par Agent
Rapports après resolve, revue, installation et une exécution limitée.
- Taux de réussite
- —
- Échec récent
- —
- Résultats
- 0
- Qualité de sortie
- —
- Échecs
- 0
- Non pertinent
- 0
- Installations
- 0
- Bloqué par le risque
- 0
- Configuration requise
- 0
- Production
- 0
Aucune donnée de résultat Agent pour l’instant. La première exécution peut signaler succès, besoin de configuration, blocage de risque, échec ou non-pertinence via /api/agent/outcome.
Installer
Ajouter au workflow Agent
Gratuit et open source. Examinez le rapport avant l’installation dans des Agents de production.
Boucle de croissance
Kit de partage
Brouillon guidé par scénario pour cognee-permissions, prêt pour une publication manuelle sur X.
cognee-permissions: Use when working with cognee's permission system — understanding or changing how users, roles... 30.2K stars https://www.openagentskill.com/skills/topoteretes-cognee-permissions?ref=x
Réponse facultative avec commande d’installation
Listing + install path for cognee-permissions: https://www.openagentskill.com/skills/topoteretes-cognee-permissions?ref=x Install: npx skills add topoteretes/cognee --skill cognee-permissions
Source de la fiche
Indexé par Registry
Cette fiche a été indexée à partir de sources publiques et n’est pas marquée officielle tant qu’une revendication de mainteneur n’est pas approuvée.
- Créateur
- topoteretes
- Source
- topoteretes/cognee
- Indexé par
- Index communautaire OpenAgentSkill
L’attribution renvoie au dépôt public ou au profil du créateur. Les créateurs peuvent revendiquer la fiche pour mettre à jour les signaux de propriété.
Revendiquer ce skillRevendication du propriétaire
Revendiquer cette fiche de skill
Cette fiche Indexé par Registry est attribuée à topoteretes, mais n’est pas encore marquée officielle. Revendiquez-la pour ajouter un signal de propriétaire vérifié et rendre les futures mises à jour de lancement, d’installation et d’audit plus fiables.
Kit de backlinks créateur
Ajoutez les badges de preuve à votre README
Affichez la fiche canonique, les signaux actuels de confiance et d’audit, ainsi que de vraies preuves Agent-Proven là où les développeurs évaluent le dépôt.
[](https://www.openagentskill.com/skills/topoteretes-cognee-permissions)
[](https://www.openagentskill.com/skills/topoteretes-cognee-permissions)
[](https://www.openagentskill.com/skills/topoteretes-cognee-permissions/audit)
[](https://www.openagentskill.com/skills/topoteretes-cognee-permissions)Auteur
topoteretes
@topoteretes
Tags
Adéquation plateforme
Signaux de santé
- Stars GitHub
- 30.2K
- Score de qualité
- 55/100
- Dernier push GitHub
- 23 août 2026
- Indications de framework
- Inconnu
- Vues OpenAgentSkill
- 0
- Copies d’installation
- 0
- Clics sortants
- 0
Signal de communauté
Indiquez si ce skill semble utile à votre workflow Agent. Les retours agrégés améliorent le classement au fil du temps.
Confiance et sécurité
Sandbox uniquement
- Adoption GitHub30K stars GitHubValidé
- Activité stars/forks30K stars et 3.0K forks; l’activité des issues n’est pas disponible dans les métadonnées actuellesValidé
- Maintenance récenteMis à jour aujourd’huiValidé
- Clarté de licenceApache-2.0Validé
- Complétude README/SKILL.mdLes métadonnées publiques nécessitent davantage de contexte README/SKILL.mdInfo
- Risque dépendances/runtimenetwork or browser surface, database surfaceInfo
Skills associés
Last30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
53.5K StarsAcademic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
38.4K StarsGPT Researcher
Run autonomous deep research over web and local sources
28.0K StarsDeepResearch
Tongyi Deep Research, the Leading Open-source Deep Research Agent
19.8K Stars