DecisionManager
Back to Blog & Articles
AI & Governance·8 min·2026-08-05

Permissions Matrix, Limits, and Workspace Administration: The Admin Console Depth

The Admin console's Permissions Matrix, Limits, and Usage pages complete the enterprise administration story: granular permission overrides beyond the four default tiers, per-workspace execution limits, and real-time usage dashboards with AI spend tracking.

Amira Tazi

Amira Tazi

Platform Architect

The four-tier RBAC model (Rule Author, Reviewer, Admin, Audit Observer) covers most governance requirements. For regulated enterprises that need granular overrides — 'this reviewer can approve in project A but not project B', 'this author can deploy to staging but not production' — the Permissions Matrix provides per-subject, per-resource overrides.

**Permissions Matrix**: a cross-referenced grid of subjects (members, groups) against resources (projects, rulesets, environments) with permission cells (allow / deny / inherit). Export in CSV for access review documentation. Inherits from the four-tier model for unset cells.

**Limits**: per-workspace execution limits — step budget cap (max steps per execution before SERVICE_BUDGET_EXCEEDED), concurrent execution cap, daily execution volume cap, and AI token budget cap. Limits prevent runaway usage from misconfigured clients and cap AI spend from a single workspace. Each limit has a soft threshold (warning) and a hard threshold (reject).

**AI Spend Spike panel**: the Admin AI console includes a spend spike detector — if a single provider's token usage spikes beyond the workspace's configured threshold in a rolling window, the panel fires with the provider, the model, the requesting service, and the spike magnitude. The diagnosis is generated by the same audit brief capability that reads audit events: the model is given the usage rows and asked what changed in the workspace's AI behaviour that might explain the spike.

**Usage dashboard**: real-time execution counts, AI token spend by provider and model, webhook delivery rates, and warehouse write throughput — all in one view. Filterable by project, by ruleset, by environment, and by time window. Export to CSV for billing attribution or capacity planning.

**Mail configuration**: the Admin console's Mail page configures outgoing email for governance notifications — 'version submitted for review', 'review approved', 'version published'. SMTP or SendGrid; template per event type; configurable sender name and reply-to. Governed by the same workspace membership as every other admin action.

Target Topics & Keywords

#BRMS permissions#workspace limits#AI spend tracking#admin console BRMS#decision manager admin#rule engine administration

Ready to evaluate DecisionManager?

Plans without a public rate card. Live demo runs in the browser with no signup. ODM export inventory stays on your machine. Free trial — no card, does not auto-convert.