OpenRouter AI access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On OpenRouter AI, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenRouter AI connector needs.
Checks (5)
severity: medium Guardrail Without Provider Allowlist fix difficulty: medium #
Restrict the guardrail to an explicit set of allowed providers
- Open the guardrail in the workspace settings
- Add an allowed-providers list so requests cannot route to arbitrary providers
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Guardrail Without Model Allowlist fix difficulty: medium #
Restrict the guardrail to an explicit set of allowed models
- Open the guardrail in the workspace settings
- Add an allowed-models list so users cannot access arbitrary models
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium BYOK Credential Without Workspace Scope fix difficulty: medium #
Scope the BYOK credential to a specific workspace
- Open the BYOK credential in Settings → Provisioning Keys
- Restrict it to the workspace(s) that need it instead of leaving it org-wide
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium SCIM Group Grants Admin Role fix difficulty: medium #
Review the SCIM group's admin role mapping
- Open Settings → SCIM in the OpenRouter dashboard
- Confirm the group genuinely needs admin, or map it to a lower role
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium SCIM Group Mapped to Default Workspace fix difficulty: medium #
Map the SCIM group to a specific workspace instead of the default one
- Open Settings → SCIM in the OpenRouter dashboard
- Edit the group's workspace mapping to a purpose-specific workspace
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2