bRRAInOps · Foundation
v2.0

bRRAIn Certified Access Controller

Design and run bRRAIn access: tiers, custom roles, project permissions, SSO, tokens, external access and reviews.

Level
Foundation
Learning time
15 hours
Price
$499
Credential
Valid 2 years
What's new in v2.0

What changed in this edition.

  • Teaches the real permission model: seven tiers, custom roles capped at Operator that replace tier defaults, and capability scopes, instead of v1's open-ended role hierarchies and zone-based permission grids.
  • New lessons on per-project Read / Add / Update / Delete permissions, Nexus surface scopes, and why every new scope means revisiting custom roles.
  • Identity rebuilt around OIDC SSO (Okta, Entra ID, Google) with highest-privilege-wins claim mapping, plus Login with bRRAIn, Google and GitHub sign-in, invitations and personal access tokens. SAML content removed.
  • Joint-session authorization and methodology enforcement are now taught as procedures built from real mechanisms (custom roles, two recorded approvals, the hash-chained audit log, Add-only grants, Correction & Supersession), with no claims of features that do not exist.
  • New coverage of non-human actors, MCP scopes, the LLM Registry, Tool Registry and Operator ENV, and of auditor access through Robo Compliance.
  • Re-levelled to Foundation: 15 hours, five AI role-play labs plus a capstone, and a new LOFT exam with AI-scored performance tasks.
Outcomes

What you will be able to do.

  • You will be able to trace any access decision through identity, tier, custom role, scopes and project or folder reach, and fix it at the right layer.
  • You will be able to map an organization onto the seven tiers and build least-privilege custom roles, and keep them correct as the scope catalog grows.
  • You will be able to configure per-project and folder permissions, including confidential projects and write-only drop boxes, and predict effective access.
  • You will be able to federate OIDC single sign-on with a safe claim mapping and govern invitations, personal access tokens and sessions.
  • You will be able to provision, evaluate, co-approve and terminate external, auditor and cross-organization access with two recorded approvals.
  • You will be able to run access reviews, mover and leaver revocation and break-glass using the audit log and decision records, and govern non-human actors and registries.

Who it's for

  • IAM (Identity and Access Management) practitioners
  • IT administrators who run a bRRAIn organization's console
  • IT security engineers moving into AI infrastructure
  • GRC professionals with access-governance responsibility

Not covered here

  • Audit execution and conformance verification (see Security Controller: the Access Controller designs and operates; the Security Controller verifies)
  • Setting organizational policy (see Operations Controller)
  • Installing and upgrading the brain pod (see Installation Specialist)
Syllabus

7 modules, 59 lessons.

About 15 hours of learning. Open a module to see every lesson.

  1. The bRRAIn Access Model 8 lessons · 1 h 42 min

    Identity, role and permission as bRRAIn implements them: sign-in routes and actor types, the seven tiers, capability scopes and their resolution order, the controller authority split, decision records, and the console screens you will use every week.

    1. Module 1 pretest Diagnostic pretest · 5 min
    2. The access chain: identity, role, permission Reading · 15 min
    3. Identity: who is calling, and how bRRAIn knows Reading · 15 min
    4. Roles: the seven tiers and custom roles Reading · 15 min
    5. Permissions: scopes and how a check is decided Reading · 15 min
    6. Who decides what: Operations, Access and Security Controllers Reading · 12 min
    7. Worked example: your weekly console route Worked example · 15 min
    8. Retrieval: Module 1 check Retrieval check · 10 min
  2. Role and Custom-Role Design 9 lessons · 2 h 19 min

    Map access patterns to tiers, apply least privilege, build and test custom roles in the role editor, avoid the four anti-patterns, revisit custom roles when the scope catalog grows, and absorb reorganizations.

    1. Module 2 pretest Diagnostic pretest · 5 min
    2. Mapping an organization onto tiers and custom roles Reading · 15 min
    3. Least privilege by default Reading · 15 min
    4. Worked example: building a custom role in the role editor Worked example · 15 min
    5. The role-design anti-patterns Reading · 15 min
    6. When the scope catalog grows: revisiting custom roles Reading · 12 min
    7. Keeping the design intact through reorganizations Scenario · 12 min
    8. Lab 1: Design the role catalog for a 150-person firm AI role-play lab · 40 min
    9. Retrieval: Module 2 check Retrieval check · 10 min
  3. Scopes, Nexus Surfaces and Project Permissions 8 lessons · 2 h 4 min

    The scope catalog by area, Nexus surface scopes, per-project Read / Add / Update / Delete permissions, folder scopes and how they compose, the pod's tier rule for confidential work, and monthly drift detection.

    1. Module 3 pretest Diagnostic pretest · 5 min
    2. The scope catalog, area by area Reading · 15 min
    3. Nexus surface scopes Reading · 12 min
    4. Per-project permissions: Read, Add, Update, Delete Worked example · 15 min
    5. Composing scopes, project rows and folder rows Worked example · 15 min
    6. Detecting and correcting permission drift Scenario · 12 min
    7. Lab 2: Configure project access for a confidential engagement AI role-play lab · 40 min
    8. Retrieval: Module 3 check Retrieval check · 10 min
  4. Identity, Single Sign-On and Tokens 8 lessons · 1 h 59 min

    OIDC federation with Okta, Entra ID and Google; claim mapping with highest-privilege-wins and a default-role floor; Login with bRRAIn, Google and GitHub sign-in and invitations; personal access tokens, client tokens and sessions; and debugging sign-in and access problems.

    1. Module 4 pretest Diagnostic pretest · 5 min
    2. SSO with OpenID Connect: Okta, Entra ID and Google Reading · 15 min
    3. Claim mapping: from identity-provider groups to tiers Worked example · 15 min
    4. Sign-in options and onboarding Reading · 12 min
    5. Tokens and sessions: PATs, client tokens and session lifetime Reading · 15 min
    6. Debugging sign-in and access problems Scenario · 12 min
    7. Lab 3: Fix a broken SSO go-live with the identity administrator AI role-play lab · 35 min
    8. Retrieval: Module 4 check Retrieval check · 10 min
  5. External and Cross-Organization Access 9 lessons · 2 h 16 min

    Contractors, partners and advisors; external auditors through Robo Compliance's auditor portal; the joint-session procedure for cross-organization access; evaluating scope requests; dual authorization by the Access and Security Controllers; and complete termination.

    1. Module 5 pretest Diagnostic pretest · 5 min
    2. Contractors, partners and advisors Reading · 15 min
    3. External auditors: evidence without membership Reading · 12 min
    4. Cross-organization access: the joint-session procedure Reading · 15 min
    5. Evaluating a scope request Worked example · 15 min
    6. Dual authorization in practice Scenario · 12 min
    7. Terminating external access mid-engagement Scenario · 12 min
    8. Lab 4: Evaluate a cross-organization access request with the Security Controller AI role-play lab · 40 min
    9. Retrieval: Module 5 check Retrieval check · 10 min
  6. Decisions, Methodology Records and Findings 9 lessons · 2 h 5 min

    Your authority over the 9-stage Build Methodology as a method: protecting records with Add-only grants and named custodians, the [Human] / [AI+Human] / [AI] attribution scheme, POPE tags and corrections under the Correction & Supersession standard, recorded exceptions, and remediation of Security Controller findings.

    1. Module 6 pretest Diagnostic pretest · 5 min
    2. The build methodology and your authority over it Reading · 15 min
    3. Attribution: one honest scheme for who decided Reading · 12 min
    4. Stage records in practice: plans before builds Worked example · 12 min
    5. Protecting recorded material: POPE tags, corrections and Add-only grants Reading · 12 min
    6. Exceptions: legitimate, recorded and temporary Scenario · 12 min
    7. Working with the Security Controller on findings Scenario · 12 min
    8. Lab 5: Make an engagement's records trustworthy AI role-play lab · 35 min
    9. Retrieval: Module 6 check Retrieval check · 10 min
  7. Access Operations and Non-Human Actors 8 lessons · 2 h 6 min

    Access reviews with the hash-chained audit log, mover and leaver revocation, break-glass emergency access, non-human actors and MCP scopes, and governance of the LLM Registry, Tool Registry, Operator ENV and integrations. Ends with the capstone.

    1. Module 7 pretest Diagnostic pretest · 5 min
    2. Access reviews with the audit log Reading · 15 min
    3. Movers and leavers: revocation checklists Worked example · 12 min
    4. Break-glass: emergency access that leaves evidence Reading · 12 min
    5. Non-human actors: services, agents, MCP clients and SDK integrations Reading · 15 min
    6. Registries, credentials and integrations: governing where AI can reach Reading · 12 min
    7. Retrieval: Module 7 check Retrieval check · 10 min
    8. Capstone: Present the access architecture for a 250-person financial-services firm AI role-play lab · 45 min
Labs and capstone

Practice against someone who pushes back.

Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.

  • Lab 1 · Role and Custom-Role Design

    AI role-play with a COO: design the role catalog for a 150-person consultancy currently all on Operator

  • Lab 2 · Scopes, Nexus Surfaces and Project Permissions

    AI role-play with a strategy officer: configure project access for a confidential engagement with externals and a scanning service

  • Lab 3 · Identity, Single Sign-On and Tokens

    AI role-play with an Okta administrator: diagnose and fix four SSO go-live tickets

  • Lab 4 · External and Cross-Organization Access

    AI role-play with a Security Controller: evaluate and co-approve a cross-organization access request

  • Lab 5 · Decisions, Methodology Records and Findings

    AI role-play with a Head of Delivery: make an engagement's methodology records trustworthy after an audit finding

  • Lab 6 · Access Operations and Non-Human Actors

    AI role-play panel with an Operations Controller and a Security Controller: present and defend a full access architecture

Capstone

Present the access architecture for a 250-person financial-services firm

AI role-play scored against the published rubric

Pass mark: 70%

Scored on

  • Role and tier design20%
  • Scopes and reach (confidentiality)20%
  • Identity, SSO and tokens15%
  • External and cross-organization access15%
  • Records protection and methodology authority10%
  • Access operations and non-human actors20%
Exam and credential

One exam. A credential anyone can verify.

The exam

Items per form
47
Time allowed
75 min
Pass mark
70%
Performance tasks
2
Attempts included
2
Wait between attempts
7 days
  • Online and timed, taken on learn.brrain.io.
  • Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
  • Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.

The credential

  • A verifiable digital badge in your name.
  • A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
  • Valid for 2 years.
  • Renewal: At 2 years, by passing the then-current exam
Before and after

Where this course sits.

Stacks well with

Questions

Frequently asked.

Do I need to install anything for the labs?

No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.

How is the exam delivered?

Online and timed: 47 items in 75 minutes, on a form assembled for you from the course's item bank. 2 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 70%.

What if I don't pass first time?

You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.

How long is the credential valid?

2 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.

I hold the v1 credential. Is it still valid?

Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.

Can my company enroll a team?

Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.

Enroll

bRRAIn Certified Access Controller

Design and run bRRAIn access: tiers, custom roles, project permissions, SSO, tokens, external access and reviews.