Map Ideogram Owner, Admin, and Member roles to application-owned tenant, budget, key, media, publishing, and audit permissions. Use when designing or reviewing enterprise access control. Trigger with "design Ideogram RBAC", "audit Ideogram team roles", or "separate Ideogram duties".
Keep Ideogram team administration distinct from application authorization. Vendor roles govern a shared team boundary, while the application must enforce tenant, use-case, spend, upload, generation, review, publication, retention, and incident permissions.
Ideogram documents Owner, Admin, and Member team roles. Team members share keys, credits, and billing context; separate keys do not inherently provide per-user or per-environment vendor budgets. Avoid inventing finer Ideogram permissions that the application must actually enforce.
Store each server-side IDEOGRAM_API_KEY in the approved secret manager and send it only as Api-Key to https://api.ideogram.ai. Users authenticate to the application; only constrained service identities reach the vendor adapter.
Use Read, Glob, and Grep for manifests, policy, identity mappings, and audit evidence. Use Write and Edit for approved policy or tests. Do not change team members, roles, keys, billing, or production identities by invocation alone.
Require authorized administrators for vendor membership, role, key, and billing changes. Require application and data owners for tenant permissions, publication, retention, and deletion. Break-glass access must expire and be reviewed.
Return vendor-role and application-permission matrices, identities, scopes, separation-of-duty findings, tests, exceptions, owners, remediation, review date, and rollback. Exclude keys and personal or media content.
Test every allow and deny edge, cross-tenant and cross-environment access, deprovisioning, rotation, audit completeness, and break-glass expiry. Confirm no role grants direct browser access to the vendor key.
88dcf65
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.