-
Notifications
You must be signed in to change notification settings - Fork 0
feat: implement granular tool access sub-constraints #220
Copy link
Copy link
Closed
Labels
prio:mediumShould do, but not blockingShould do, but not blockingscope:medium1-3 days of work1-3 days of workspec:securityDESIGN_SPEC Section 12 - Security & Approval SystemDESIGN_SPEC Section 12 - Security & Approval Systemspec:toolsDESIGN_SPEC Section 11 - Tool & Capability SystemDESIGN_SPEC Section 11 - Tool & Capability Systemtype:featureNew feature implementationNew feature implementationv0.7Minor version v0.7Minor version v0.7v0.7.2Patch release v0.7.2Patch release v0.7.2
Metadata
Metadata
Assignees
Labels
prio:mediumShould do, but not blockingShould do, but not blockingscope:medium1-3 days of work1-3 days of workspec:securityDESIGN_SPEC Section 12 - Security & Approval SystemDESIGN_SPEC Section 12 - Security & Approval Systemspec:toolsDESIGN_SPEC Section 11 - Tool & Capability SystemDESIGN_SPEC Section 11 - Tool & Capability Systemtype:featureNew feature implementationNew feature implementationv0.7Minor version v0.7Minor version v0.7v0.7.2Patch release v0.7.2Patch release v0.7.2
Summary
ToolPermissionCheckercurrently implements category-level gating only. The spec defines granular sub-constraints per access level (workspace scope, network mode, containerization level, git access mode).Design Spec Reference
Scope
file_systemscope,networkmode,gitaccess,code_executionisolation levelcustomaccess level support with per-agent configuration