bRRAIn Certified Access Controller
Design and run bRRAIn access: tiers, custom roles, project permissions, SSO, tokens, external access and reviews.
- Level
- Foundation
- Learning time
- 15 hours
- Price
- $499
- Credential
- Valid 2 years
What changed in this edition.
- Teaches the real permission model: seven tiers, custom roles capped at Operator that replace tier defaults, and capability scopes, instead of v1's open-ended role hierarchies and zone-based permission grids.
- New lessons on per-project Read / Add / Update / Delete permissions, Nexus surface scopes, and why every new scope means revisiting custom roles.
- Identity rebuilt around OIDC SSO (Okta, Entra ID, Google) with highest-privilege-wins claim mapping, plus Login with bRRAIn, Google and GitHub sign-in, invitations and personal access tokens. SAML content removed.
- Joint-session authorization and methodology enforcement are now taught as procedures built from real mechanisms (custom roles, two recorded approvals, the hash-chained audit log, Add-only grants, Correction & Supersession), with no claims of features that do not exist.
- New coverage of non-human actors, MCP scopes, the LLM Registry, Tool Registry and Operator ENV, and of auditor access through Robo Compliance.
- Re-levelled to Foundation: 15 hours, five AI role-play labs plus a capstone, and a new LOFT exam with AI-scored performance tasks.
What you will be able to do.
- You will be able to trace any access decision through identity, tier, custom role, scopes and project or folder reach, and fix it at the right layer.
- You will be able to map an organization onto the seven tiers and build least-privilege custom roles, and keep them correct as the scope catalog grows.
- You will be able to configure per-project and folder permissions, including confidential projects and write-only drop boxes, and predict effective access.
- You will be able to federate OIDC single sign-on with a safe claim mapping and govern invitations, personal access tokens and sessions.
- You will be able to provision, evaluate, co-approve and terminate external, auditor and cross-organization access with two recorded approvals.
- You will be able to run access reviews, mover and leaver revocation and break-glass using the audit log and decision records, and govern non-human actors and registries.
Who it's for
- IAM (Identity and Access Management) practitioners
- IT administrators who run a bRRAIn organization's console
- IT security engineers moving into AI infrastructure
- GRC professionals with access-governance responsibility
Not covered here
- Audit execution and conformance verification (see Security Controller: the Access Controller designs and operates; the Security Controller verifies)
- Setting organizational policy (see Operations Controller)
- Installing and upgrading the brain pod (see Installation Specialist)
7 modules, 59 lessons.
About 15 hours of learning. Open a module to see every lesson.
-
The bRRAIn Access Model
Identity, role and permission as bRRAIn implements them: sign-in routes and actor types, the seven tiers, capability scopes and their resolution order, the controller authority split, decision records, and the console screens you will use every week.
- Module 1 pretest
- The access chain: identity, role, permission
- Identity: who is calling, and how bRRAIn knows
- Roles: the seven tiers and custom roles
- Permissions: scopes and how a check is decided
- Who decides what: Operations, Access and Security Controllers
- Worked example: your weekly console route
- Retrieval: Module 1 check
-
Role and Custom-Role Design
Map access patterns to tiers, apply least privilege, build and test custom roles in the role editor, avoid the four anti-patterns, revisit custom roles when the scope catalog grows, and absorb reorganizations.
- Module 2 pretest
- Mapping an organization onto tiers and custom roles
- Least privilege by default
- Worked example: building a custom role in the role editor
- The role-design anti-patterns
- When the scope catalog grows: revisiting custom roles
- Keeping the design intact through reorganizations
- Lab 1: Design the role catalog for a 150-person firm
- Retrieval: Module 2 check
-
Scopes, Nexus Surfaces and Project Permissions
The scope catalog by area, Nexus surface scopes, per-project Read / Add / Update / Delete permissions, folder scopes and how they compose, the pod's tier rule for confidential work, and monthly drift detection.
- Module 3 pretest
- The scope catalog, area by area
- Nexus surface scopes
- Per-project permissions: Read, Add, Update, Delete
- Composing scopes, project rows and folder rows
- Detecting and correcting permission drift
- Lab 2: Configure project access for a confidential engagement
- Retrieval: Module 3 check
-
Identity, Single Sign-On and Tokens
OIDC federation with Okta, Entra ID and Google; claim mapping with highest-privilege-wins and a default-role floor; Login with bRRAIn, Google and GitHub sign-in and invitations; personal access tokens, client tokens and sessions; and debugging sign-in and access problems.
- Module 4 pretest
- SSO with OpenID Connect: Okta, Entra ID and Google
- Claim mapping: from identity-provider groups to tiers
- Sign-in options and onboarding
- Tokens and sessions: PATs, client tokens and session lifetime
- Debugging sign-in and access problems
- Lab 3: Fix a broken SSO go-live with the identity administrator
- Retrieval: Module 4 check
-
External and Cross-Organization Access
Contractors, partners and advisors; external auditors through Robo Compliance's auditor portal; the joint-session procedure for cross-organization access; evaluating scope requests; dual authorization by the Access and Security Controllers; and complete termination.
- Module 5 pretest
- Contractors, partners and advisors
- External auditors: evidence without membership
- Cross-organization access: the joint-session procedure
- Evaluating a scope request
- Dual authorization in practice
- Terminating external access mid-engagement
- Lab 4: Evaluate a cross-organization access request with the Security Controller
- Retrieval: Module 5 check
-
Decisions, Methodology Records and Findings
Your authority over the 9-stage Build Methodology as a method: protecting records with Add-only grants and named custodians, the [Human] / [AI+Human] / [AI] attribution scheme, POPE tags and corrections under the Correction & Supersession standard, recorded exceptions, and remediation of Security Controller findings.
- Module 6 pretest
- The build methodology and your authority over it
- Attribution: one honest scheme for who decided
- Stage records in practice: plans before builds
- Protecting recorded material: POPE tags, corrections and Add-only grants
- Exceptions: legitimate, recorded and temporary
- Working with the Security Controller on findings
- Lab 5: Make an engagement's records trustworthy
- Retrieval: Module 6 check
-
Access Operations and Non-Human Actors
Access reviews with the hash-chained audit log, mover and leaver revocation, break-glass emergency access, non-human actors and MCP scopes, and governance of the LLM Registry, Tool Registry, Operator ENV and integrations. Ends with the capstone.
- Module 7 pretest
- Access reviews with the audit log
- Movers and leavers: revocation checklists
- Break-glass: emergency access that leaves evidence
- Non-human actors: services, agents, MCP clients and SDK integrations
- Registries, credentials and integrations: governing where AI can reach
- Retrieval: Module 7 check
- Capstone: Present the access architecture for a 250-person financial-services firm
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · Role and Custom-Role Design
AI role-play with a COO: design the role catalog for a 150-person consultancy currently all on Operator
-
Lab 2 · Scopes, Nexus Surfaces and Project Permissions
AI role-play with a strategy officer: configure project access for a confidential engagement with externals and a scanning service
-
Lab 3 · Identity, Single Sign-On and Tokens
AI role-play with an Okta administrator: diagnose and fix four SSO go-live tickets
-
Lab 4 · External and Cross-Organization Access
AI role-play with a Security Controller: evaluate and co-approve a cross-organization access request
-
Lab 5 · Decisions, Methodology Records and Findings
AI role-play with a Head of Delivery: make an engagement's methodology records trustworthy after an audit finding
-
Lab 6 · Access Operations and Non-Human Actors
AI role-play panel with an Operations Controller and a Security Controller: present and defend a full access architecture
Present the access architecture for a 250-person financial-services firm
AI role-play scored against the published rubric
Pass mark: 70%
Scored on
- Role and tier design20%
- Scopes and reach (confidentiality)20%
- Identity, SSO and tokens15%
- External and cross-organization access15%
- Records protection and methodology authority10%
- Access operations and non-human actors20%
One exam. A credential anyone can verify.
The exam
- Items per form
- 47
- Time allowed
- 75 min
- Pass mark
- 70%
- Performance tasks
- 2
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 2 years.
- Renewal: At 2 years, by passing the then-current exam
Where this course sits.
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 47 items in 75 minutes, on a form assembled for you from the course's item bank. 2 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 70%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
2 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
bRRAIn Certified Access Controller
Design and run bRRAIn access: tiers, custom roles, project permissions, SSO, tokens, external access and reviews.