Agent skill

Glean Enterprise Rbac

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Map AD/Okta groups to Glean document permissions using allowedGroups.

MITAuto-check passedBackend & APIs

Install Glean Enterprise Rbac

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-enterprise-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace glean-enterprise-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/glean-enterprise-rbac .claude/skills/glean-enterprise-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
glean-enterprise-rbac
GitHub stars
2.8k
Token cost
~1.5k tokens
SKILL.md length
478 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Map AD/Okta groups to Glean document permissions using allowedGroups.

  • Works in 5 steps: Map source ACL groups to opaque target… → Stage the change on a low-risk… → Promote only when both tests match the… → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Overview, Role Hierarchy, Permission Check and Role Assignment, plus 9 more sections
  • Needs GLEAN_API_TOKEN

What it does

Glean Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Map AD/Okta groups to Glean document permissions using allowedGroups. Trigger: "glean enterprise rbac", "enterprise-rbac".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Authorization and RBAC. It works with Okta. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Tasks that involve Authorization and RBAC

Example prompts

  • “glean enterprise rbac”
  • “enterprise-rbac”
  • “/glean-enterprise-rbac”

Requirements

  • A credential in GLEAN_API_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Map source ACL groups to opaque target groups and require a one-to-one owner approval for every expanded access path.
  2. Stage the change on a low-risk datasource, then run the allow and deny test identities against a fictitious document identifier.
  3. Promote only when both tests match the source ACL; otherwise restore the prior mapping and investigate the IdP or connector sync boundary.
  4. Log the actor, change request, datasource, mapping revision, and outcomes without query text, document titles, or user email addresses.
  5. Recheck after the next identity synchronization and revoke the mapping immediately if it grants access beyond the approved scope.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npm:*)
    • Bash(curl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.glean.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GLEAN_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Glean Enterprise Rbac loads about 1.5k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 478 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 478 words, ~1,468 tokens.

Download SKILL.mdSave it as .claude/skills/glean-enterprise-rbac/SKILL.md (or your agent's skills folder).
name
glean-enterprise-rbac
description
Map AD/Okta groups to Glean document permissions using allowedGroups. Trigger: "glean enterprise rbac", "enterprise-rbac".
allowed-tools
Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep
compatibility
Designed for Claude Code
version
1.8.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, enterprise-search, glean

Glean Enterprise RBAC

Overview

Glean's enterprise search aggregates content from dozens of connectors (Google Drive, Confluence, Slack, Salesforce). RBAC ensures users only see documents they are authorized to access. Permissions flow from source systems through connector-level ACLs into Glean's unified index. Misconfigured permissions mean search results leak sensitive data across teams. SOC 2 and GDPR compliance require document-level access control and full audit trails on who searched what.

Role Hierarchy

RolePermissionsScope
Super AdminCreate API tokens, manage all connectors, configure SSOOrganization-wide
AdminAdd/edit datasources, manage user groups, view analyticsAssigned datasources
Content ManagerSet document permissions, manage allowedGroups per datasourceOwn datasources
UserSearch and view permitted documentsDocuments matching ACLs
ViewerSearch only, no document previews or snippetsRestricted document set

Permission Check

typescript
async function checkDocumentAccess(userId: string, documentId: string): Promise<boolean> {
  const response = await fetch(`${GLEAN_API}/permissions/check`, {
    method: 'POST',
    headers: { Authorization: `Bearer ${GLEAN_API_TOKEN}`, 'Content-Type': 'application/json' },
    body: JSON.stringify({ userId, documentId }),
  });
  const result = await response.json();
  return result.hasAccess ?? false;
}

Role Assignment

typescript
async function assignDatasourceRole(email: string, datasource: string, role: 'admin' | 'viewer'): Promise<void> {
  await fetch(`${GLEAN_API}/datasources/${datasource}/permissions`, {
    method: 'PUT',
    headers: { Authorization: `Bearer ${GLEAN_API_TOKEN}`, 'Content-Type': 'application/json' },
    body: JSON.stringify({ user: email, role, allowedGroups: [`${datasource}-${role}s`] }),
  });
}

async function revokeDatasourceAccess(email: string, datasource: string): Promise<void> {
  await fetch(`${GLEAN_API}/datasources/${datasource}/permissions/${email}`, {
    method: 'DELETE',
    headers: { Authorization: `Bearer ${GLEAN_API_TOKEN}` },
  });
}

Audit Logging

typescript
interface GleanAuditEntry {
  timestamp: string; userId: string; action: 'search' | 'view' | 'index' | 'permission_change';
  datasource: string; query?: string; documentId?: string; result: 'allowed' | 'denied';
}

function logSearchAccess(entry: GleanAuditEntry): void {
  console.log(JSON.stringify({ ...entry, org: process.env.GLEAN_ORG_ID }));
}

RBAC Checklist

  • Each connector maps source-system ACLs to Glean allowedGroups
  • API tokens scoped per datasource, not organization-wide
  • SAML/SSO groups synced with Glean user groups daily
  • Document-level permissions verified after each connector sync
  • Search analytics reviewed monthly for unauthorized access patterns
  • Token rotation policy enforced quarterly
  • Sensitive datasources restricted to named allowedGroups only

Error Handling

IssueCauseFix
User sees documents from wrong teamAllowedGroups not mapped to connectorReconfigure connector ACL mapping in admin console
403 Forbidden on search APIExpired or wrong-scope API tokenRegenerate token with correct datasource scope
Stale permissions after IdP changeConnector sync lagTrigger manual resync from Glean admin
Missing search resultsOverly restrictive allowedGroupsAudit group membership against source system ACLs

Prerequisites

  • A source-of-truth group inventory, named data owner, and two synthetic test identities: one authorized and one explicitly denied.
  • A least-privilege admin role that can stage a mapping in one non-production datasource without changing organization-wide access.
  • A rollback record capturing the prior mapping by opaque group ID; never place real group membership exports or search results in tickets.
Show full SKILL.md (171 more words)Show less

Instructions

  1. Map source ACL groups to opaque target groups and require a one-to-one owner approval for every expanded access path.
  2. Stage the change on a low-risk datasource, then run the allow and deny test identities against a fictitious document identifier.
  3. Promote only when both tests match the source ACL; otherwise restore the prior mapping and investigate the IdP or connector sync boundary.
  4. Log the actor, change request, datasource, mapping revision, and outcomes without query text, document titles, or user email addresses.
  5. Recheck after the next identity synchronization and revoke the mapping immediately if it grants access beyond the approved scope.

Output

Produce an RBAC change receipt: datasource, prior and new mapping revisions, approving owner, staged/production status, synthetic allow and deny outcomes, sync watermark, and rollback reference. The receipt must contain only opaque IDs and aggregate counts.

Examples

Example: datasource=staging-contracts; mapping_rev=42; owner=legal-ops; allow_probe=pass; deny_probe=pass; sync=2026-08-27T14:00Z; rollback=rev41. This proves the boundary without disclosing membership or content.

Resources

Next Steps

See glean-security-basics.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/.curated/glean-enterprise-rbac of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Glean Enterprise Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Glean Enterprise Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Glean Enterprise Rbac this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.5kAutomated safety check: PassMIT
Frontmcp Authoritiesagentfront/frontmcp146—~7.1kAutomated safety check: PassApache-2.0
Implementing Device Posture Assessment In Zero Trustmukul975/Anthropic-Cybersecurity-Skills34k—~4.1kAutomated safety check: PassApache-2.0
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Spring Security JWTrrezartprebreza/spring-boot-skills301—~1.7kAutomated safety check: PassMIT
Cometchat Securitycometchat/cometchat-skills132—~1.9kAutomated safety check: PassMIT

Similar skills

  • Frontmcp Authorities

    agentfront/frontmcp

    A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.

    146 GitHub stars~7.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Implementing Device Posture Assessment In Zero Trust

    mukul975/Anthropic-Cybersecurity-Skills

    Implements device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that…

    34k GitHub stars~4.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Spring Security JWT

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security.

    301 GitHub stars~1.7k tokensUpdated 19 days ago
    Backend & APIsAuto-check passed
  • Cometchat Security

    cometchat/cometchat-skills

    Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group…

    132 GitHub stars~1.9k tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Glean Enterprise Rbac

What does Glean Enterprise Rbac do?

Map AD/Okta groups to Glean document permissions using allowedGroups. Glean Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Map AD/Okta groups to Glean document permissions using allowedGroups.

When should I use Glean Enterprise Rbac?

Glean Enterprise Rbac fits situations like: tasks that involve Authorization and RBAC.

How do I install Glean Enterprise Rbac in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-enterprise-rbac -a claude-code`. Or copy the skill folder (skills/.curated/glean-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/glean-enterprise-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Glean Enterprise Rbac in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-enterprise-rbac -a codex`. Or copy the skill folder (skills/.curated/glean-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/glean-enterprise-rbac in your project. Codex loads it when a task matches its description.

Can I use Glean Enterprise Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill glean-enterprise-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/glean-enterprise-rbac, .gemini/skills/glean-enterprise-rbac, .github/skills/glean-enterprise-rbac and .opencode/skills/glean-enterprise-rbac in your project.

What does Glean Enterprise Rbac need to run?

Going by SKILL.md and its folder, Glean Enterprise Rbac needs credentials named GLEAN_API_TOKEN. Our summary lists: A credential in GLEAN_API_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npm:*), Bash(curl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Glean Enterprise Rbac access the network?

SKILL.md names 1 domain. As links in the text: developers.glean.com. This is read from the text; nothing was executed.

Is Glean Enterprise Rbac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Glean Enterprise Rbac use?

Glean Enterprise Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Glean Enterprise Rbac use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Glean Enterprise Rbac?

Skills that share tags, products or a category with Glean Enterprise Rbac: Frontmcp Authorities (agentfront/frontmcp, 146 stars), Implementing Device Posture Assessment In Zero Trust (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars) and Spring Security JWT (rrezartprebreza/spring-boot-skills, 301 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Glean Enterprise Rbac?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.