Skip to content

Agent roles that follow the stop boundaries (read now, operate when needed) #2467

Description

@shiny-code-app

Objective

Give the operator's agent a standing role instead of one-off grants. The roles follow the stop boundaries in DIRECTION.md, so the permission system enforces the direction.

Who Can do
Operator (admin, policy administrator) everything
Operator's agent: read read every Launchplane record (granted 2026-09-23 per DIRECTION.md: "Reading is never a stop")
Operator's agent: operate ordinary writes on products that are not live, such as preview, testing deploys, and product setup
Operator only writes to live sites, grants, credentials, and who can merge

An agent is never an admin: an admin can grant itself anything, and agents granting themselves authority caused earlier drift (for example #2239).

Trigger

Waiting on purpose. Start this issue when refused agent writes stop work twice, per the tool rule: fix a tool at its cause once it has stopped work twice. Until then, a refused write is a stop boundary, so ask the operator once.

Context

Agreed with the operator in the 2026-09-23 direction session. Launchplane has no groups today. People have admin or read_only roles, and every machine identity holds only its enumerated grants (docs/authorization-authority.md).

Current Status

State: waiting for the trigger above.
Next action: none until the trigger fires. Then design the smallest "operate" grant set, and have the operator apply it.
Last verified: 2026-09-23.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    planDurable planning issueplan:waitingPlan is waiting on non-issue evidence or decision

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions