Deepgram Enterprise RbacCAUTION
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: deepgram-enterprise-rbac description: 'Configure enterprise role-based access control for Deepgram integrations. Use when implementing team permissions, managing API key scopes, or setting up organization-level access controls. Trigger: "deepgram RBAC", "deepgram permissions", "deepgram access control", "deepgram team roles", "deepgram enterprise", "deepgram key scopes". ' allowed-tools: Read, Write, Edit, Bash(curl:*) version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - deepgram - api - rbac - enterprise compatibility: Designed for Claude Code --- # Deepgram Enterprise RBAC ## Prerequisites - A verified identity source, named project/role owners, least-privilege role map, and access-review schedule. - Authority to provision/revoke users and service credentials through approved identity/admin paths. ## Examples Grant a transcription service account only the development project scope it needs, validate its permitted action with a synthetic fixture, and record the owner and expiration/review date. Confirm that the same identity cannot access production; on role mismatch, revoke the broad assignment and correct the group mapping before further use. ## Overview Role-based access control for enterprise Deepgram deployments. Maps five application roles to Deepgram API key scopes, implements scoped key provisioning via the Deepgram Management API, Express permission middleware, team management with auto-provisioned keys, and automated key rotation. ## Deepgram Scope Reference | Scope | Permission | Used By | |-------|-----------|---------| | `member` | Full access (all scopes) | Admin only | | `listen` | STT transcription | Developers, Services | | `speak` | TTS synthesis | Developers, Services | | `manage` | Project/key management | Admin | | `usage:read` | View usage metrics | Analysts, Auditors | | `keys:read` | List API keys | Auditors | | `keys:write` | Create/delete keys | Admin | ## Instructions ### Step 1: Define Roles and Scope Mapping ```typescript interface Role { name: string; deepgramScopes: string[]; keyExpiry: number; // Days description: string; } const ROLES: Record<string, Role> = { admin: { name: 'Admin', deepgramScopes: ['member'], keyExpiry: 90, description: 'Full access — project and key management', }, developer: { name: 'Developer', deepgramScopes: ['listen', 'speak'], keyExpiry: 90, description: 'STT and TTS — no management access', }, analyst: { name: 'Analyst', deepgramScopes: ['usage:read'], keyExpiry: 365, description: 'Read-only usage metrics', }, service: { name: 'Service Account', deepgramScopes: ['listen'], keyExpiry: 90, description: 'STT only — for automated systems', }, auditor: { name: 'Auditor', deepgramScopes: ['usage:read', 'keys:read'], keyExpiry: 30, description: 'Read-only audit access', }, }; ``` ### Step 2: Scoped Key Provisioning ```typescript import { createClient } from '@deepgram/sdk'; class DeepgramKeyManager { private admin: ReturnType<typeof createClient>; private projectId: string; constructor(adminKey: string, projectId: string) { this.admin = createClient(adminKey); this.projectId = projectId; } async createScopedKey(userId: string, roleName: string): Promise<{ keyId: string; key: string; scopes: string[]; expiresAt: string; }> { const role = ROLES[roleName]; if (!role) throw new Error(`Unknown role: ${roleName}`); const expirationDate = new Date(Date.now() + role.keyExpiry * 86400000); const { result, error } = await this.admin.manage.createProjectKey( this.projectId, { comment: `${roleName}:${userId}:${new Date().toISOString().split('T')[0]}`, scopes: role.deepgramScopes, expiration_date: expirationDate.toISOString(), } ); if (error) throw new Error(`Key creation failed: ${error.message}`); console.log(`Created ${roleName} key for ${userId} (expires ${expirationDate.toISOString().split('T')[0]})`); return { keyId: result.key_id, key: result.key, scopes: role.deepgramScopes, expiresAt: expirationDate.toISOString(), }; } async revokeKey(keyId: string) { const { error } = await this.admin.manage.deleteProjectKey( this.projectId, keyId ); if (error) throw new Error(`Key revocation failed: ${error.message}`); console.log(`Revoked key: ${keyId}`); } async listKeys() { const { result, error } = await this.admin.manage.getProjectKeys(this.projectId); if (error) throw error; return result.api_keys.map((k: any) => ({ keyId: k.api_key_id, comment: k.comment, scopes: k.scopes, created: k.created, expiration: k.expiration_date, })); } } ``` ### Step 3: Permission Middleware ```typescript import { Request, Response, NextFunction } from 'express'; interface AuthenticatedRequest extends Request { user?: { id: string; role: string; deepgramKeyId: string }; } function requireRole(...allowedRoles: string[]) { return (req: AuthenticatedRequest, res: Response, next: NextFunction) => { if (!req.user) { return res.status(401).json({ error: 'Authentication required' }); } if (!allowedRoles.includes(req.user.role)) { console.warn(`Access denied: user ${req.user.id} (${req.user.role}) tried to access ${req.path}`); return res.status(403).json({ error: 'Insufficient permissions', required: allowedRoles, current: req.user.role, }); } next(); }; } function requireScope(...requiredScopes: string[]) { return (req: AuthenticatedRequest, res: Response, next: NextFunction) => { if (!req.user) { return res.status(401).json({ error: 'Authentication required' }); } const role = ROLES[req.user.role]; const hasScopes = requiredScopes.every( s => role
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
| `keys:read` | List API keys | Auditors |
| `member` | Full access (all scopes) | Admin only |
description: 'Full access — project and key management',
admin: { name: 'Administrator', description: 'Full access', deepgramScopes: ['manage:*', 'listen:*', 'usage:*', 'keys:*'], appPermissions: ['*'] },Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__deepgram-enterprise-rbac.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | CAUTION | B | 89 | first audit |
Questions
What does the Deepgram Enterprise Rbac skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Deepgram Enterprise Rbac safe to install?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Deepgram Enterprise Rbac access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Deepgram Enterprise Rbac work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.