Add Project & Workspace MCP System with role-based permissions

- Add roboco_project_* tools (list, get, create, update) with CEO bypass
  - Add roboco_workspace_* tools (ensure, status, list) for workspace management
  - Add project_slug and requires_git fields to TaskCreateInput schema
  - Validate project exists and cell matches when creating git-enabled tasks
  - Register project MCP server in orchestrator with proper permissions

  Workspace permissions by role:
  - Developer: Write to own workspace only
  - QA: Read-only access to all cell workspaces
  - Documenter: Write to all cell workspaces (add docs to dev branches)
  - Cell PM: Write to own workspace, project_update for own cell
  - Main PM: Full project access (create, update all, workspace_list all)
  - CEO: Full bypass on all permission checks

  Also includes:
  - Git templates for commits, branches, PRs (separation of concerns)
  - Updated blueprints with project/workspace tools documentation
  - Updated RAG docs with project tools reference
This commit is contained in:
Renn F
2026-01-07 22:45:42 +01:00
parent 363ab6c0ce
commit f1c5b7958c
42 changed files with 2967 additions and 493 deletions
+14
View File
@@ -63,3 +63,17 @@ Native tools are blocked; use `roboco_*` MCP tools instead.
**Blocked:**
- All write operations - observer role
## Project Tools
| Tool | Dev/QA/Doc | Cell PM | Main PM | CEO |
|------|------------|---------|---------|-----|
| `roboco_project_list` | Own cell | Own cell | All | All |
| `roboco_project_get` | Yes | Yes | Yes | Yes |
| `roboco_project_create` | No | No | Yes | Yes |
| `roboco_project_update` | No | Own cell | All | All |
| `roboco_workspace_ensure` | Yes | Yes | Yes | Yes |
| `roboco_workspace_status` | Yes | Yes | Yes | Yes |
| `roboco_workspace_list` | No | Own cell | All | All |
**CEO Bypass:** CEO has full access to all project operations.