# JAAS > JAAS is an enterprise layer on top of Juju that provides centralized controller management, OIDC authentication, and ReBAC authorization. 2026 CC-BY-SA, Canonical Group Ltd ## Pages - [JAAS documentation](https://documentation.ubuntu.com/jaas/latest/index.md): JAAS documentation covering the Juju Intelligent Model Manager (JIMM) with enterprise authentication, ReBAC authorization, and centralized Juju control. - [Get started with JAAS](https://documentation.ubuntu.com/jaas/latest/tutorial.md): Learn how to deploy JIMM (the Juju Intelligent Model Manager) on MicroK8s with enterprise authentication and centralized Juju management. - [How-to guides](https://documentation.ubuntu.com/jaas/latest/howto.md): How-to guides for JAAS operations including deployment management, controllers, clouds, models, users, groups, roles, and permissions. - [Manage your JAAS deployment](https://documentation.ubuntu.com/jaas/latest/howto/manage-your-jaas-deployment.md): Complete guide to deploying and managing JAAS with JIMM controller, OpenFGA, PostgreSQL, Vault on Kubernetes with authentication configuration. - [Manage Juju controllers](https://documentation.ubuntu.com/jaas/latest/howto/manage-juju-controllers.md): Learn how to add, remove, and manage Juju controllers in JAAS for centralized model management across multiple controllers. - [Manage clouds](https://documentation.ubuntu.com/jaas/latest/howto/manage-clouds.md): Learn how to manage clouds in JAAS, including controlling user access with permissions. - [Manage users](https://documentation.ubuntu.com/jaas/latest/howto/manage-users.md): Learn how to set up new users in JAAS, configure DNS addresses, manage login credentials, and control user access to resources. - [Manage roles](https://documentation.ubuntu.com/jaas/latest/howto/manage-roles.md): Learn how to create, rename, and manage roles in JAAS to grant users collections of permissions across resources and environments. - [Manage groups](https://documentation.ubuntu.com/jaas/latest/howto/manage-groups.md): Learn how to create, rename, and manage groups in JAAS to organize users and control access to models, clouds, and controllers. Includes migration to IdP groups. - [Manage permissions](https://documentation.ubuntu.com/jaas/latest/howto/manage-permissions.md): Learn how to add, revoke, and check permissions in JAAS for users, groups, roles, and resources including controllers, clouds, and models. - [Manage models](https://documentation.ubuntu.com/jaas/latest/howto/manage-models.md): Learn how to create, deploy, and manage Juju models in JAAS with controller placement, access control, and model lifecycle operations. - [Manage offers](https://documentation.ubuntu.com/jaas/latest/howto/manage-offers.md): Learn how to manage application offers in JAAS and control user access with permissions. - [Reference](https://documentation.ubuntu.com/jaas/latest/reference.md): Complete reference for JAAS including technical documentation, APIs, security, JAAS plugin commands, and entity specifications. - [Audit logs](https://documentation.ubuntu.com/jaas/latest/reference/audit-logs.md): Learn how to filter, query, and analyze JIMM audit logs tracking all system requests and responses with configurable retention periods. - [Cloud](https://documentation.ubuntu.com/jaas/latest/reference/cloud.md): Complete reference for JAAS cloud entities including cloud tags, permissions like administrator and can_addmodel, and access control. - [Controller](https://documentation.ubuntu.com/jaas/latest/reference/controller.md): Complete reference for JAAS controller entities including controller tags, permissions like administrator and audit-log-viewer. - [Group](https://documentation.ubuntu.com/jaas/latest/reference/group.md): Complete reference for JAAS groups including group tags, member permissions, and managing collections of users. - [JAAS](https://documentation.ubuntu.com/jaas/latest/reference/jaas.md): JAAS reference documentation including supported Juju versions for deployment, CLI usage, and controller compatibility requirements. - [Supported Juju versions](https://documentation.ubuntu.com/jaas/latest/reference/jaas/jaas-supported-juju-versions.md): Learn JAAS supported Juju versions for deployment, CLI usage, and controller compatibility with minimum version requirements and LTS support. - [`jaas` plugin](https://documentation.ubuntu.com/jaas/latest/reference/jaas-plugin.md): Complete guide to the JAAS plugin CLI tool for Juju including installation via Snap and extended functionality for JAAS systems. - [jaas add-cloud](https://documentation.ubuntu.com/jaas/latest/reference/list-of-jaas-plugin-commands.md): Add cloud to specific controller in jimm - [Model](https://documentation.ubuntu.com/jaas/latest/reference/model.md): Complete reference for JAAS model entities including model tags, permissions like reader, writer, and administrator access levels. - [Offer](https://documentation.ubuntu.com/jaas/latest/reference/offer.md): Complete reference for JAAS application offers including offer tags, permissions like administrator, consumer, and reader access. - [Role](https://documentation.ubuntu.com/jaas/latest/reference/role.md): Complete reference for JAAS roles including role tags, assignee permissions, and managing entity capabilities in JIMM controllers. - [User](https://documentation.ubuntu.com/jaas/latest/reference/user.md): Complete reference for JAAS users including user tags, domain identification, external users, and group and role memberships. - [Explanation](https://documentation.ubuntu.com/jaas/latest/explanation.md): Understand JAAS concepts including reference architecture, authentication, authorization, ReBAC with OpenFGA, and security overview. - [Architecture](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-architecture.md): Understand JAAS architecture with JIMM, ReBAC authorization, OpenFGA, PostgreSQL database, and Vault secure storage components. - [Authentication](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-authentication.md): Understand JAAS authentication with OAuth 2.0 and OIDC, external identity providers, and how it differs from Juju local users. - [Authorization](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-authorization.md): Understand JAAS authorization with Relationship-Based Access Control (ReBAC) for flexible user permissions on controllers, models, and resources. - [ReBAC admin backend](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-rebac-admin-backend.md): Learn about the ReBAC Admin REST API for querying and manipulating relationships in JAAS authorization model with OpenAPI specification. - [Security overview](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-security.md): Comprehensive JAAS security overview covering cloud credentials, Vault storage, TLS communication, asymmetric cryptography, and data protection. - [Security scope](https://documentation.ubuntu.com/jaas/latest/explanation/jaas-security-scope.md): Understand JAAS security scope including secure communication, TLS encryption, access control, authentication, and identity provider integration. - [Reference architecture](https://documentation.ubuntu.com/jaas/latest/explanation/reference-architecture.md): JAAS reference architecture covering automation, OAuth2/OIDC authentication, ReBAC authorization, Juju CLI, and Terraform Provider integration.