vastai-enterprise-rbac
Installation
SKILL.md
Native Vast.ai Team and Key Governance
Overview
Use the platform's Teams and permission-category model instead of inventing an application-only proxy. Separate human roles from automation keys, constrain high-risk endpoints when possible, and prove both required access and expected denial.
Prerequisites
- Team owner and inventory of members, services, resources, and environments
- Actor-by-action matrix for instance, user, billing, machine, miscellaneous, and team categories
- Joiner, mover, leaver, emergency-access, and periodic-review procedures
Instructions
Step 1: Model responsibilities
Map each actor to read and write operations. Keep billing-write, team-write, machine-write, and instance destruction separate unless a documented duty requires them.