Skip to content

OpenRouter AI access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On OpenRouter AI, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the OpenRouter AI connector needs.

Checks (5)

severity: medium Guardrail Without Provider Allowlist fix difficulty: medium #

Restrict the guardrail to an explicit set of allowed providers

  1. Open the guardrail in the workspace settings
  2. Add an allowed-providers list so requests cannot route to arbitrary providers

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Guardrail Without Model Allowlist fix difficulty: medium #

Restrict the guardrail to an explicit set of allowed models

  1. Open the guardrail in the workspace settings
  2. Add an allowed-models list so users cannot access arbitrary models

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium BYOK Credential Without Workspace Scope fix difficulty: medium #

Scope the BYOK credential to a specific workspace

  1. Open the BYOK credential in Settings → Provisioning Keys
  2. Restrict it to the workspace(s) that need it instead of leaving it org-wide

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium SCIM Group Grants Admin Role fix difficulty: medium #

Review the SCIM group's admin role mapping

  1. Open Settings → SCIM in the OpenRouter dashboard
  2. Confirm the group genuinely needs admin, or map it to a lower role

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium SCIM Group Mapped to Default Workspace fix difficulty: medium #

Map the SCIM group to a specific workspace instead of the default one

  1. Open Settings → SCIM in the OpenRouter dashboard
  2. Edit the group's workspace mapping to a purpose-specific workspace

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More OpenRouter AI checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial