Role Profiles (RBAC)
Table of Contents
Section titled “Table of Contents”- Overview & RBAC Architecture
- Business & Operational Significance
- 🎯 User Roles & Key Capabilities
- Visual Interface & Layout
- Granular Permission Matrix & CRUD Flags
- Protection of System Profiles & Cloning Workflow
- Official System Role Profiles
- Troubleshooting & Verification
- Model Context Protocol (MCP) AI Integration
- Glossary
1. Overview & RBAC Architecture
Section titled “1. Overview & RBAC Architecture”In Ring2All SBC, the Role Profiles module provides granular Role-Based Access Control (RBAC) across all user interface modules, REST endpoints, and backend administration services. Rather than granting coarse, binary access levels, the SBC enforces four discrete boolean operational permissions for every system module:
- Read / List (
can_read): Authorizes viewing list DataGrids, summary metric cards, and individual record details. - Create / Insert (
can_create): Authorizes accessing/newcreation forms and submittingPOSTrequests. - Edit / Update (
can_edit): Authorizes modifying existing configurations and submittingPUT/PATCHrequests. - Delete / Destroy (
can_delete): Authorizes purging records viaDELETEendpoints and clicking destructive UI actions.
Incoming API / UI Request │ ▼┌──────────────────────────────────────────────┐│ Authenticated Session Context ││ (user_id, role_profile_id) │└──────────────────────┬───────────────────────┘ │ ▼┌──────────────────────────────────────────────┐│ Role Profile Module Lookup ││ Target: "routing.carriers" | Action: EDIT │└──────────────────────┬───────────────────────┘ │ ┌──────────────┴──────────────┐ │ │ ▼ ▼[can_edit == true] [can_edit == false] Permit Action Reject (403 Forbidden) Render Save Button Disable / Hide ControlsThis ensures that administrative privileges conform strictly to the Principle of Least Privilege (PoLP) across complex carrier operations.
2. Business & Operational Significance
Section titled “2. Business & Operational Significance”- Prevention of Accidental Routing Disruptions: Allows Tier-1 helpdesk personnel to inspect active call traces and CDRs without the risk of accidentally modifying carrier routing rules or reloading Kamailio dispatchers.
- Regulatory Compliance & Separation of Duties: Satisfies strict compliance mandates (PCI-DSS, SOC 2, HIPAA) by guaranteeing that operators cannot alter both security firewall rules and financial billing rate cards.
- Safe Delegation to Third-Party Carriers: Enables wholesale carriers to access a dedicated portal view to inspect their own DID numbers and interconnection quality metrics without exposing other tenants.
- Immutability of Core Protections: Built-in system profiles are cryptographically and structurally shielded from deletion or tampering, preventing administrative lockouts.
3. 🎯 User Roles & Key Capabilities
Section titled “3. 🎯 User Roles & Key Capabilities”| Role | Primary Use Case | Key Capabilities |
|---|---|---|
| SBC Security Officer | Permission Policy Design | Define custom role profiles, enforce four-flag segregation, and audit administrative permission assignments. |
| Telecom Operations Manager | Operational Role Delegation | Assign specific role profiles to NOC shift engineers, LCR specialists, and provisioning clerks. |
| Compliance Auditor | Privilege Governance | Review permissions across all active profiles and verify that no accounts hold excessive unmonitored privileges. |
| Infrastructure Administrator | System Profile Protection | Verify that core system profiles remain locked and duplicate profiles for staging environments. |
| AI Platform Copilot / Administration Agent | Automated RBAC Auditing & Privilege Analysis | Programmatically list role profiles, verify module permissions matrices, audit user assignments, and detect privilege escalation risks via MCP. |
4. Visual Interface & Layout
Section titled “4. Visual Interface & Layout”The Role Profiles interface consists of a profile catalog view displaying system vs custom profiles, along with a granular permission matrix editor organized by functional module groups.
4.1 Role Profiles List View
Section titled “4.1 Role Profiles List View”Displays all defined role profiles, their system/custom status, total assigned modules, and contextual action buttons (Edit, Copy, Delete).

4.2 Role Profile Configuration Form
Section titled “4.2 Role Profile Configuration Form”Form modal presenting the full permission matrix across all SBC modules with independent Read, Create, Edit, and Delete checkboxes.

5. Granular Permission Matrix & CRUD Flags
Section titled “5. Granular Permission Matrix & CRUD Flags”The permission matrix covers all functional modules of Ring2All SBC, categorized into logical groups:
| Module Category | Target Modules Included | Standard Operations |
|---|---|---|
| Routing | SIP Domains, MS Teams, Endpoints, Carriers, Quality Routing, SIP Accounts, DIDs, Outbound Routes, STIR/SHAKEN | Read carrier lists, add new DIDs, modify LCR priority, enable STIR/SHAKEN certificates. |
| CDR Reports | Call Detail Records, QoS & Voice Quality, SIP Traces, System Audit Logs | Search CDR streams, export CSVs, analyze MOS ladders, review administrative audit trails. |
| Technology Settings | Engine Settings, Billing & OCS, HA Cluster, Push Notifications, Media Engines, TLS Profiles | Tune Kamailio worker concurrency, adjust OCS endpoints, manage RTPEngine nodes, renew TLS keys. |
| Logic & Trees | Memory Trees (MTrees), SIP Manipulation Rules (SMR), Hash Tables (HTables) | Edit prefix trees, define regex rewrite rules, flush or unblock banned IP addresses. |
| Tools | Config Editor (kamailio.cfg), RPC Console (kamcmd) |
Validate and save core scripts, execute live JSON-RPC diagnostic commands. |
| Administration | Users, Role Profiles, MCP Roles, Log Profiles, API Keys, Carrier API Keys, Email, Languages | Create user accounts, assign permission profiles, generate REST tokens, configure SMTP alerts. |
6. Protection of System Profiles & Cloning Workflow
Section titled “6. Protection of System Profiles & Cloning Workflow”System-generated profiles are protected by multi-tier safety mechanisms:
[System Profile (is_system = true)] │ ├── Delete Action: DISABLED (Hidden in DataGrid and Form ActionBar) ├── Backend Guard: 400 Bad Request if deletion is attempted via REST │ └── Copy Action: ALWAYS AVAILABLE ──► Clones matrix to "Profile_copy" Allows full customization- Deletion Guard: Both the web frontend and the Fastify backend reject any deletion request targeting a profile marked
is_system = trueoris_default = true. - Duplication Workflow (
Copy): Operators can click the Copy action on any system profile. The platform immediately creates a duplicate record (<Name> Copy) with identical permissions, allowing safe customization without altering the baseline system configuration.
7. Official System Role Profiles
Section titled “7. Official System Role Profiles”Ring2All SBC includes four official baseline profiles:
| Profile Name | Module Scope | Access Level | Description |
|---|---|---|---|
| Administrator | All Modules (100%) | FULL (CRUD) |
Unrestricted root administrative access across all routing, security, and administrative modules. |
| NOC Operator | Routing, Reports, Tools, Logic | READ + EDIT |
Designed for 24/7 network operations center engineers to monitor traffic, inspect traces, and unban IPs. |
| Telecom Auditor | Reports, Routing, Technology | READ ONLY |
Read-only visibility for billing reconciliation analysts, compliance officers, and executive dashboards. |
| LCR Specialist | Routing, MTrees, Carrier Trunks | READ + WRITE |
Dedicated to carrier interconnect managers managing tariffs, routing groups, and prefix matching. |
8. Troubleshooting & Verification
Section titled “8. Troubleshooting & Verification”Inspecting Role Profiles in Database
Section titled “Inspecting Role Profiles in Database”Verify active profiles and system flags directly on the SBC host:
sudo -u postgres psql -d sbc_admin -c "SELECT id, name, description, is_system, is_default, created_atFROM role_profilesORDER BY id;"Validating Profile Permission Payload
Section titled “Validating Profile Permission Payload”Check the permissions assigned to a specific role profile ID (e.g., ID 2):
sudo -u postgres psql -d sbc_admin -c "SELECT module_slug, can_read, can_create, can_edit, can_deleteFROM role_profile_permissionsWHERE role_profile_id = 2LIMIT 10;"9. Model Context Protocol (MCP) AI Integration
Section titled “9. Model Context Protocol (MCP) AI Integration”Ring2All SBC exposes dedicated Model Context Protocol (MCP) tools enabling AI agents, autonomous NOC bots, and administrative copilot assistants to query, audit, and analyze role-based access control policies.
Available MCP Tools
Section titled “Available MCP Tools”| Tool Name | Operation | Risk Level | Description |
|---|---|---|---|
list_sbc_role_profiles |
Read | Low (read) |
List all RBAC role profiles defined in Ring2All SBC with assigned user counts, default flags, and system protections. |
get_sbc_role_profile |
Read | Low (read) |
Retrieve the complete granular permission matrix (read, create, edit, delete) for a specific role profile by UUID, slug, or name. |
Tool Schemas & Parameter Definitions
Section titled “Tool Schemas & Parameter Definitions”list_sbc_role_profiles
Section titled “list_sbc_role_profiles”{ "name": "list_sbc_role_profiles", "description": "List RBAC role profiles defined in Ring2All SBC with assigned user counts and permission summaries.", "inputSchema": { "type": "object", "properties": {} }}get_sbc_role_profile
Section titled “get_sbc_role_profile”{ "name": "get_sbc_role_profile", "description": "Get full permission matrix and details for a specific RBAC role profile by UUID, slug, or name.", "inputSchema": { "type": "object", "properties": { "identifier": { "type": "string", "description": "Role UUID, slug, or name" } }, "required": ["identifier"] }}Realistic Payload Examples
Section titled “Realistic Payload Examples”Query Request (get_sbc_role_profile)
Section titled “Query Request (get_sbc_role_profile)”{ "identifier": "noc-operator"}Successful Response (get_sbc_role_profile)
Section titled “Successful Response (get_sbc_role_profile)”{ "success": true, "data": { "roleProfile": { "id": 2, "uuid": "7c98f12a-35b4-4e20-911d-88ab1e42f009", "name": "NOC Operator", "slug": "noc-operator", "description": "Designed for 24/7 network operations center engineers to monitor traffic, inspect traces, and unban IPs.", "is_system": true, "is_default": false, "is_active": true, "users_count": 8, "permissions": { "routing.carriers": { "can_read": true, "can_create": false, "can_edit": true, "can_delete": false }, "routing.dids": { "can_read": true, "can_create": true, "can_edit": true, "can_delete": false }, "reports.sip_traces": { "can_read": true, "can_create": false, "can_edit": false, "can_delete": false }, "tools.rpc_console": { "can_read": true, "can_create": false, "can_edit": true, "can_delete": false } }, "created_at": "2026-01-15T08:00:00Z", "updated_at": "2026-08-20T14:30:00Z" } }}Natural Language Prompt Scenarios
Section titled “Natural Language Prompt Scenarios”English (Access Governance Audit)
Section titled “English (Access Governance Audit)”“Audit all role profiles on Ring2All SBC and list any profile that grants delete permissions on carrier routing tables or the RPC console.”
Spanish (Inspección de Permisos de Operador)
Section titled “Spanish (Inspección de Permisos de Operador)”“Obtén los detalles y la matriz de permisos del perfil de rol ‘NOC Operator’ para verificar si los ingenieros de turno pueden reiniciar nodos dispatchers.”
Enterprise AI Safety Guardrails
Section titled “Enterprise AI Safety Guardrails”- Non-Destructive Read Guarantees:
list_sbc_role_profilesandget_sbc_role_profileoperate strictly in read-only mode, preventing unauthorized modification of security matrices by AI assistants. - System Immutability Enforcement: The backend prevents modification or deletion of profiles with
is_system = true, maintaining platform security invariants regardless of API caller identity.
10. Glossary
Section titled “10. Glossary”- RBAC (Role-Based Access Control): A method of regulating access to computer or network resources based on the roles of individual users within an enterprise.
- PoLP (Principle of Least Privilege): The security practice of granting users only the minimum access necessary to perform their jobs.
- CRUD: The four basic functions of persistent storage: Create, Read, Update, and Delete.
- System Profile: A built-in security profile marked
is_system = truethat cannot be removed from the platform.

