Usher is the access control plane for the Overture platform. It holds the grants that say what each person may see and do, hands them to each application, and gives the people who govern access one place to change them. It is closer to a keychain than a lock, with the keys handed to each application rather than to the person asking: enforcement happens inside the application at its own query layer, with no per-request call back to Usher.
Two things separate it from a conventional access control service. It governs who may grant, not only who may read, so a category's custodian holds authority over that category across every dataset while holding no access to any of it. And it fails closed: an application that loses contact with Usher stops serving the affected data rather than coasting on its cache.
Usher is not an authentication service. Authentication is delegated to the configured identity provider (Keycloak, Microsoft Entra ID, or any OIDC-compatible provider).
Usher is part of Overture, a collection of open-source software microservices used to create platforms for researchers to organize and share genomics data.
Status: design phase. No implementation exists yet. All current work is design and planning. See the Design Index for the corresponding documentation.
Operational documentation waits on implementation. What exists now explains the problem and the model:
| Document | For |
|---|---|
| Onboarding | A plain-language orientation to the model and the reasoning behind it, written for readers who are not engineers. Rendered and published as a shared page; the file itself is the source |
| Data access control | The problem and the patterns, before the design detail |
| Why Usher | Why a separate service, rather than access logic inside each application |
| Concepts and vocabulary | ABAC terms, security primitives, and the permissions model entities |
| IAM primer | Login, tokens and access control basics, for readers meeting them for the first time |
For internal contributor documentation (project structure, working documents, AI tooling, security principles), see DEVELOPMENT.md.
The Overture platform includes the following components:
| Software | Description |
|---|---|
| Score | Transfer data to and from any cloud-based storage system |
| Song | Catalogue and manage metadata associated to file data spread across cloud storage systems |
| Maestro | Organizing your distributed data into a centralized Elasticsearch index |
| Arranger | A search API with reusable UI components |
| Stage | A React-based web portal scaffolding |
| Lyric | A model-agnostic, tabular data submission system |
| Lectern | Schema Manager, designed to validate, store, and manage collections of data dictionaries |
If you'd like to get started using our platform check out our quickstart guides
Usher is not yet accepting external contributions; the project is in the design phase.
- Platform-level discussions: Overture community support
- Contribution guidelines when available: Contributing Guide
Overture is supported by grant #U24CA253529 from the National Cancer Institute at the US National Institutes of Health, and additional funding from Genome Canada, the Canada Foundation for Innovation, the Canadian Institutes of Health Research, Canarie, and the Ontario Institute for Cancer Research.