Skip to main content
tiCrypt 2.17.11

Concepts

tiCrypt differs from a traditional shared computing environment in three structural ways:

  • Encryption is per resource, not per perimeter. Each drive and file carries its own key, so protection does not depend on staying inside a trusted network.
  • Compute happens in ephemeral VMs, not on shared nodes. A machine resets on restart, so nothing persists on it by accident.
  • Operating the infrastructure does not grant access to the data on it. Administrative authority and decryption authority are separate, and no role combines them.

Read these pages before the Research, Governance, or Deploy & Operate sections. They map what you already know onto how tiCrypt behaves.

Core Concepts in 60 Seconds​

tiCrypt uses seven terms that sound similar but control different things. Skim them before reading the pages below:

  • System Role: Your level in the platform hierarchy (User, Sub-Admin, Admin, Super-Admin). It decides who you can see and manage, not what you can do.
  • User Profile: A named, reusable bundle of a system role plus granular permissions. An administrator creates profiles and applies them to users, individually or in bulk. It is not a personal settings page, and users do not edit their own.
  • VM Role: Who you are inside a particular virtual machine (Owner, Co-Owner, Manager, User).
  • VM Permissions: What that role lets you do inside that machine. Set per VM, and they take precedence over your system permissions: being an Admin grants nothing inside a VM.
  • Team: The unit that holds resource quotas. Every user belongs to at least one team, and a user removed from all teams is deactivated.
  • Project: A security boundary. Tagging a resource with a project restricts it to members certified for that project.
  • Group: A named set of collaborators you share with in one action. Membership drives access: adding a member grants them everything already shared with the group, and removing a member revokes it. A group carries no quota and no authority of its own, which is what separates it from a team and from a project.
PageWho it helpsWhat it covers
From Shared Computing Cluster to tiCryptResearchers and IT staff migrating from a shared computing or HPC environmentConcept-by-concept mapping table, dual Slurm architecture, data lifecycle, quick-start checklist
Institutional Role MappingPIs, lab managers, IT directors setting up tiCrypt for a research groupHow to compose system roles, user profiles, and VM roles to reproduce institutional personas
VM Roles and PermissionsAnyone working with tiCrypt virtual machinesHow Owner, Co-Owner, Manager, and User roles work inside a VM, independently from the main system