Modal is launching Role-Based Access Control (RBAC) for all Team and Enterprise plan users, designed to manage access for both human developers and AI agents. The system is built around Environments as enforceable security boundaries, allowing teams to create Restricted Environments where only explicitly granted users or service accounts can deploy or manage resources. Key features include per-environment storage and app isolation, read-only defaults for workspace members in restricted zones, cross-environment lookup restrictions, and integration with Audit Logs. The roadmap includes spending/time-based limits per agent, programmatic permission access, and making Restricted Environments the default.
Table of contents
Environments as secure access boundariesUnderstanding Restricted EnvironmentsWhat’s next74 Impressions