> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cedarai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# IAM Concepts

> Users, groups, resources, permissions, roles, and conditions.

<Info>
  This page explains the **conceptual foundation** of IAM. To manage these concepts in practice, use the [Admin Portal](/user-docs/admin/overview).
</Info>

## Identities

<Tabs>
  <Tab title="Users">
    Email-based ARMS accounts. Access is granted through roles on resources across ARMS products (e.g., inventory, transload, intermodal, mobile).

    |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Username | Identifier                                                       |
    | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ---------------------------------------------------------------- |
    | <img width="100" src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/001-man.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=1d6aef7d73987e8ad4a6c4860a0aa33c" data-path="images/iam/001-man.png" />                 | Mike     | user:[mike@cedx.rail](mailto:mike@cedx.rail)                     |
    | <img width="100" src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/002-woman.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=9675c8a5ee2c7bb2147e5d3e08d65500" data-path="images/iam/002-woman.png" /> | Kacey    | user:[kecey@cedx.rail](mailto:kecey@cedx.rail)                   |
    | <img width="100" src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/017-woman.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=8aaba692ac45cbcf228355cd0285a76c" data-path="images/iam/017-woman.png" /> | Heather  | user:[heather@monstersugar.net](mailto:heather@monstersugar.net) |
    | <img width="100" src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/040-man.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=551812b925a25036368293366fb15024" data-path="images/iam/040-man.png" />                 | Bob      | user:[bob@monstersugar.net](mailto:bob@monstersugar.net)         |
  </Tab>

  <Tab title="Groups">
    Organize users and assign access at scale across multiple ARMS modules.

    |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Group               | Identifier              | Description                                                                                                  |
    | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------- | ----------------------- | ------------------------------------------------------------------------------------------------------------ |
    | <img width="100" src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/001-man.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=1d6aef7d73987e8ad4a6c4860a0aa33c" data-path="images/iam/001-man.png" />                 | CEDX Admin          | group:cedxadmin         | Has access to everything in the ARMS system that belongs to CEDX                                             |
    | <img width="100" src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/002-woman.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=9675c8a5ee2c7bb2147e5d3e08d65500" data-path="images/iam/002-woman.png" /> | CEDX User           | group:cedxuser          | Conditionally allowed to access some parts of the system                                                     |
    | <img width="100" src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/017-woman.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=8aaba692ac45cbcf228355cd0285a76c" data-path="images/iam/017-woman.png" /> | CEDX Customer Admin | group:cedxcustomeradmin | Can access customer tracks and certain groups, load and unload cars on customer tracks, and print paperworks |
    | <img width="100" src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/040-man.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=551812b925a25036368293366fb15024" data-path="images/iam/040-man.png" />                 | CEDX Customer User  | group:cedxcustomeruser  | Can only print paperworks                                                                                    |
  </Tab>

  <Tab title="Example resources">
    These are example resources used in this guide. Replace with your own organization’s resources (e.g., sites, terminals, customers, or operators).

    <Columns cols={2}>
      <Card title="CEDX Railroad" icon="train">
        <img src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/train.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=99f8ea8f3d841d71fe08d48d48b68a79" alt="CEDX Railroad" width="100" data-path="images/iam/train.png" />
      </Card>

      <Card title="Sugar Factory" icon="building-2">
        <img src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/factory.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=2839ed03397a4eb2727995558692c4dd" alt="Sugar Factory" width="100" data-path="images/iam/factory.png" />
      </Card>
    </Columns>
  </Tab>
</Tabs>

## Resources

Equipment, groups, waybills, sites, terminals, operators, workflows, and more. Permissions can be granted at an organization/site/operator level, at a sub‑area (e.g., terminal or group/track), or at an individual resource level.

### Resource hierarchy and inheritance

Permissions granted at a higher‑level resource are inherited by child resources.

* Organization / Operator / Site → applies to all sub‑resources below
* Terminal / Group / Track → applies to resources in that sub‑area only
* Specific resource → applies only to that one resource

## Permissions and roles

* Permissions: `service.resource.verb` (e.g., `inventorymanagement.equipment.list`)
* Roles: collections of permissions
  * Predefined roles (curated)
  * [Feature sets](/user-docs/iam/feature-sets) — the columns of the Admin Portal IAM matrix; Cedar keeps each one current as features grow, so roles built on them don't drift
  * Custom roles (tailored — best built by checking feature-set columns rather than picking individual permissions)

## How IAM works

Policies attach to resources and bind members to roles, with optional conditions. On access, ARMS evaluates the target resource’s policy to allow or deny—consistently across all ARMS modules.

<Card title="Policy evaluation" icon="binary">
  Policy = Bindings of `{ role, members, optional condition }`. Conditions use a simplified CEL expression syntax.
</Card>

<img src="https://mintcdn.com/cedaraiinc/3XL8_nY45kQdoBAs/images/iam/iam.png?fit=max&auto=format&n=3XL8_nY45kQdoBAs&q=85&s=e74e76d1ddd813454a5375bfef4c9dbd" alt="IAM diagram" width="800" data-path="images/iam/iam.png" />

## Conditions (optional)

Scope access by attributes. Examples:

```json theme={null}
{
  "description": "Only BNSF cars",
  "expression": "resource.equipmentInitial == 'BNSF'"
}
```

```json theme={null}
{
  "description": "Tracks A or B",
  "expression": "resource.track in ['A','B']"
}
```

## Manage these concepts in the Admin Portal

<CardGroup cols={2}>
  <Card title="Users" href="/user-docs/admin/users" icon="user">
    Create and manage user accounts
  </Card>

  <Card title="User Groups" href="/user-docs/admin/user-groups" icon="users">
    Organize users into groups
  </Card>

  <Card title="Roles" href="/user-docs/admin/roles" icon="key">
    View and create roles with permissions
  </Card>

  <Card title="Bindings" href="/user-docs/admin/bindings" icon="link">
    Connect groups to roles and scopes
  </Card>
</CardGroup>

<Tip>
  See the [Admin Portal Glossary](/user-docs/admin/glossary) for a quick reference of all terms.
</Tip>
