Skip to content

Role Profiles (RBAC)

9 min readUpdated: Sep 26, 2026
View as Markdown
  1. Overview & RBAC Architecture
  2. Business & Operational Significance
  3. 🎯 User Roles & Key Capabilities
  4. Visual Interface & Layout
  5. Granular Permission Matrix & CRUD Flags
  6. Protection of System Profiles & Cloning Workflow
  7. Official System Role Profiles
  8. Troubleshooting & Verification
  9. Model Context Protocol (MCP) AI Integration
  10. Glossary

In Ring2All SBC, the Role Profiles module provides granular Role-Based Access Control (RBAC) across all user interface modules, REST endpoints, and backend administration services. Rather than granting coarse, binary access levels, the SBC enforces four discrete boolean operational permissions for every system module:

  • Read / List (can_read): Authorizes viewing list DataGrids, summary metric cards, and individual record details.
  • Create / Insert (can_create): Authorizes accessing /new creation forms and submitting POST requests.
  • Edit / Update (can_edit): Authorizes modifying existing configurations and submitting PUT/PATCH requests.
  • Delete / Destroy (can_delete): Authorizes purging records via DELETE endpoints and clicking destructive UI actions.
Incoming API / UI Request
│
▼
┌──────────────────────────────────────────────┐
│ Authenticated Session Context │
│ (user_id, role_profile_id) │
└──────────────────────┬───────────────────────┘
│
▼
┌──────────────────────────────────────────────┐
│ Role Profile Module Lookup │
│ Target: "routing.carriers" | Action: EDIT │
└──────────────────────┬───────────────────────┘
│
┌──────────────┴──────────────┐
│ │
▼ ▼
[can_edit == true] [can_edit == false]
Permit Action Reject (403 Forbidden)
Render Save Button Disable / Hide Controls

This ensures that administrative privileges conform strictly to the Principle of Least Privilege (PoLP) across complex carrier operations.


  • Prevention of Accidental Routing Disruptions: Allows Tier-1 helpdesk personnel to inspect active call traces and CDRs without the risk of accidentally modifying carrier routing rules or reloading Kamailio dispatchers.
  • Regulatory Compliance & Separation of Duties: Satisfies strict compliance mandates (PCI-DSS, SOC 2, HIPAA) by guaranteeing that operators cannot alter both security firewall rules and financial billing rate cards.
  • Safe Delegation to Third-Party Carriers: Enables wholesale carriers to access a dedicated portal view to inspect their own DID numbers and interconnection quality metrics without exposing other tenants.
  • Immutability of Core Protections: Built-in system profiles are cryptographically and structurally shielded from deletion or tampering, preventing administrative lockouts.

Role Primary Use Case Key Capabilities
SBC Security Officer Permission Policy Design Define custom role profiles, enforce four-flag segregation, and audit administrative permission assignments.
Telecom Operations Manager Operational Role Delegation Assign specific role profiles to NOC shift engineers, LCR specialists, and provisioning clerks.
Compliance Auditor Privilege Governance Review permissions across all active profiles and verify that no accounts hold excessive unmonitored privileges.
Infrastructure Administrator System Profile Protection Verify that core system profiles remain locked and duplicate profiles for staging environments.
AI Platform Copilot / Administration Agent Automated RBAC Auditing & Privilege Analysis Programmatically list role profiles, verify module permissions matrices, audit user assignments, and detect privilege escalation risks via MCP.

The Role Profiles interface consists of a profile catalog view displaying system vs custom profiles, along with a granular permission matrix editor organized by functional module groups.

Displays all defined role profiles, their system/custom status, total assigned modules, and contextual action buttons (Edit, Copy, Delete).

Role Profiles List View

Form modal presenting the full permission matrix across all SBC modules with independent Read, Create, Edit, and Delete checkboxes.

Role Profile Configuration Form


5. Granular Permission Matrix & CRUD Flags

Section titled “5. Granular Permission Matrix & CRUD Flags”

The permission matrix covers all functional modules of Ring2All SBC, categorized into logical groups:

Module Category Target Modules Included Standard Operations
Routing SIP Domains, MS Teams, Endpoints, Carriers, Quality Routing, SIP Accounts, DIDs, Outbound Routes, STIR/SHAKEN Read carrier lists, add new DIDs, modify LCR priority, enable STIR/SHAKEN certificates.
CDR Reports Call Detail Records, QoS & Voice Quality, SIP Traces, System Audit Logs Search CDR streams, export CSVs, analyze MOS ladders, review administrative audit trails.
Technology Settings Engine Settings, Billing & OCS, HA Cluster, Push Notifications, Media Engines, TLS Profiles Tune Kamailio worker concurrency, adjust OCS endpoints, manage RTPEngine nodes, renew TLS keys.
Logic & Trees Memory Trees (MTrees), SIP Manipulation Rules (SMR), Hash Tables (HTables) Edit prefix trees, define regex rewrite rules, flush or unblock banned IP addresses.
Tools Config Editor (kamailio.cfg), RPC Console (kamcmd) Validate and save core scripts, execute live JSON-RPC diagnostic commands.
Administration Users, Role Profiles, MCP Roles, Log Profiles, API Keys, Carrier API Keys, Email, Languages Create user accounts, assign permission profiles, generate REST tokens, configure SMTP alerts.

6. Protection of System Profiles & Cloning Workflow

Section titled “6. Protection of System Profiles & Cloning Workflow”

System-generated profiles are protected by multi-tier safety mechanisms:

[System Profile (is_system = true)]
│
├── Delete Action: DISABLED (Hidden in DataGrid and Form ActionBar)
├── Backend Guard: 400 Bad Request if deletion is attempted via REST
│
└── Copy Action: ALWAYS AVAILABLE ──► Clones matrix to "Profile_copy"
Allows full customization
  1. Deletion Guard: Both the web frontend and the Fastify backend reject any deletion request targeting a profile marked is_system = true or is_default = true.
  2. Duplication Workflow (Copy): Operators can click the Copy action on any system profile. The platform immediately creates a duplicate record (<Name> Copy) with identical permissions, allowing safe customization without altering the baseline system configuration.

Ring2All SBC includes four official baseline profiles:

Profile Name Module Scope Access Level Description
Administrator All Modules (100%) FULL (CRUD) Unrestricted root administrative access across all routing, security, and administrative modules.
NOC Operator Routing, Reports, Tools, Logic READ + EDIT Designed for 24/7 network operations center engineers to monitor traffic, inspect traces, and unban IPs.
Telecom Auditor Reports, Routing, Technology READ ONLY Read-only visibility for billing reconciliation analysts, compliance officers, and executive dashboards.
LCR Specialist Routing, MTrees, Carrier Trunks READ + WRITE Dedicated to carrier interconnect managers managing tariffs, routing groups, and prefix matching.

Verify active profiles and system flags directly on the SBC host:

Terminal window
sudo -u postgres psql -d sbc_admin -c "
SELECT id, name, description, is_system, is_default, created_at
FROM role_profiles
ORDER BY id;
"

Check the permissions assigned to a specific role profile ID (e.g., ID 2):

Terminal window
sudo -u postgres psql -d sbc_admin -c "
SELECT module_slug, can_read, can_create, can_edit, can_delete
FROM role_profile_permissions
WHERE role_profile_id = 2
LIMIT 10;
"

9. Model Context Protocol (MCP) AI Integration

Section titled “9. Model Context Protocol (MCP) AI Integration”

Ring2All SBC exposes dedicated Model Context Protocol (MCP) tools enabling AI agents, autonomous NOC bots, and administrative copilot assistants to query, audit, and analyze role-based access control policies.

Tool Name Operation Risk Level Description
list_sbc_role_profiles Read Low (read) List all RBAC role profiles defined in Ring2All SBC with assigned user counts, default flags, and system protections.
get_sbc_role_profile Read Low (read) Retrieve the complete granular permission matrix (read, create, edit, delete) for a specific role profile by UUID, slug, or name.
{
"name": "list_sbc_role_profiles",
"description": "List RBAC role profiles defined in Ring2All SBC with assigned user counts and permission summaries.",
"inputSchema": {
"type": "object",
"properties": {}
}
}
{
"name": "get_sbc_role_profile",
"description": "Get full permission matrix and details for a specific RBAC role profile by UUID, slug, or name.",
"inputSchema": {
"type": "object",
"properties": {
"identifier": {
"type": "string",
"description": "Role UUID, slug, or name"
}
},
"required": ["identifier"]
}
}
{
"identifier": "noc-operator"
}

Successful Response (get_sbc_role_profile)

Section titled “Successful Response (get_sbc_role_profile)”
{
"success": true,
"data": {
"roleProfile": {
"id": 2,
"uuid": "7c98f12a-35b4-4e20-911d-88ab1e42f009",
"name": "NOC Operator",
"slug": "noc-operator",
"description": "Designed for 24/7 network operations center engineers to monitor traffic, inspect traces, and unban IPs.",
"is_system": true,
"is_default": false,
"is_active": true,
"users_count": 8,
"permissions": {
"routing.carriers": { "can_read": true, "can_create": false, "can_edit": true, "can_delete": false },
"routing.dids": { "can_read": true, "can_create": true, "can_edit": true, "can_delete": false },
"reports.sip_traces": { "can_read": true, "can_create": false, "can_edit": false, "can_delete": false },
"tools.rpc_console": { "can_read": true, "can_create": false, "can_edit": true, "can_delete": false }
},
"created_at": "2026-01-15T08:00:00Z",
"updated_at": "2026-08-20T14:30:00Z"
}
}
}

“Audit all role profiles on Ring2All SBC and list any profile that grants delete permissions on carrier routing tables or the RPC console.”

Spanish (Inspección de Permisos de Operador)

Section titled “Spanish (Inspección de Permisos de Operador)”

“Obtén los detalles y la matriz de permisos del perfil de rol ‘NOC Operator’ para verificar si los ingenieros de turno pueden reiniciar nodos dispatchers.”

  • Non-Destructive Read Guarantees: list_sbc_role_profiles and get_sbc_role_profile operate strictly in read-only mode, preventing unauthorized modification of security matrices by AI assistants.
  • System Immutability Enforcement: The backend prevents modification or deletion of profiles with is_system = true, maintaining platform security invariants regardless of API caller identity.

  • RBAC (Role-Based Access Control): A method of regulating access to computer or network resources based on the roles of individual users within an enterprise.
  • PoLP (Principle of Least Privilege): The security practice of granting users only the minimum access necessary to perform their jobs.
  • CRUD: The four basic functions of persistent storage: Create, Read, Update, and Delete.
  • System Profile: A built-in security profile marked is_system = true that cannot be removed from the platform.