Conversation
Re-scoped 2026-10-02: grants, not per-action approval. Three capabilities join skills.manage (ent#596) in the closed set: - schedules.manage: schedule create/update/delete/enable/disable and the webhook routes on ANOTHER agent. An agent's own schedules stay free (#2996); trigger is not fenced. - instructions.manage: CLAUDE.md, AGENTS.md and .claude/** except skills through the file routes, plus git reset-to-main-preserve-state. Not grantable to a calibrating companion (ent#663). - agents.manage: durable create, delete, deploy-local, systems/deploy, the chat model, and the read-only/resources/timeout/ public-channel-model/guardrails writes (now person-or-grant). Ghost spawn and discard are exempt (ent#69). Without the grant, an agent gets a named 403 (*_management_not_permitted). The 403 tells the agent to raise a permission-request ask and says an admin grants the permission in Settings. Every refusal is audited. Autonomy, api-key-setting, capabilities, capacity and rename stay person-only. New: GET/PUT /api/agents/{name}/capability-grants[/{capability}], with PUT limited to an interactive admin and audited; this is the backend for ent#756. The route census gains a person_or_grant class. Related to Abilityai/trinity-enterprise#164 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
|
merge-train (2026-10-05, evening run): not on this train. It rides the next one once fixed. CI is green at Blocking
Needs a decision before it lands
Mechanical, for the same push
What held up: the grant route is human-only against every key type tried, the own-agent and ghost exemptions are not spoofable, the table already exists on both migration tracks, and |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements the re-scoped abilityai/trinity-enterprise#164 (2026-10-02): grants, not per-action approval. An agent key resolves to its owner (Invariant #8), so until now any agent could reshape any agent of the same owner. ent#596 closed this for skills. This PR extends the same capability-grant seam to the rest of an agent's shape.
schedules.managetriggerinstructions.manageCLAUDE.md,AGENTS.mdand.claude/**except skills, through the file routes;git/reset-to-main-preserve-stateagents.managedeploy-local,systems/deploy,PUT /model, andread-only/resources/timeout/public-channel-model/guardrailsHow it behaves:
*_management_not_permitted).ask_class: permission-request. Approving that ask does not grant anything; an admin grants the permission in Settings.capability_refused.trinity-systemare never fenced.instructions.manage(422calibrating_agent, ent#663).New routes (the backend for ent#756's Settings toggles):
GET /api/agents/{name}/capability-grants: owner-level. Returns all four capabilities, held or not, with who granted each and when.PUT /api/agents/{name}/capability-grants/{capability}{granted}: admin and interactive, idempotent, audited.After deploy, no agent holds the three new capabilities. An orchestrating agent that does any of the following gets a 403 until an admin grants the permission:
Self-scheduling and ghost spawning keep working.
Decisions taken (2026-10-05)
agents.manage.agents.managecovers every reconfigure route. bug(auth): agent-scoped keys can toggle their own agent's autonomy — PUT /api/agents/{name}/autonomy lacks reject_agent_principal #2996's PERSON rule becomes PERSON-or-grant for those five routes; autonomy stays strictly PERSON.schedules.manage..claude/skills/**staysskills.manageonly.Tests
tests/unit/test_ent164_self_change_grants.py(40 tests):test_2996_owner_config_person_only.py: real keys through the realget_current_userand grant table.test_2996_human_only_routes.py: new census classperson_or_grant; the GET route is listedagent_callablewith a reason.test_ent679_*. Those fail identically with this change stashed (ModuleNotFoundError: payments_py.a2a.inband, local venv only).Not in this PR
Related to abilityai/trinity-enterprise#164
🤖 Generated with Claude Code