Add Project & Workspace MCP System with role-based permissions

- Add roboco_project_* tools (list, get, create, update) with CEO bypass
  - Add roboco_workspace_* tools (ensure, status, list) for workspace management
  - Add project_slug and requires_git fields to TaskCreateInput schema
  - Validate project exists and cell matches when creating git-enabled tasks
  - Register project MCP server in orchestrator with proper permissions

  Workspace permissions by role:
  - Developer: Write to own workspace only
  - QA: Read-only access to all cell workspaces
  - Documenter: Write to all cell workspaces (add docs to dev branches)
  - Cell PM: Write to own workspace, project_update for own cell
  - Main PM: Full project access (create, update all, workspace_list all)
  - CEO: Full bypass on all permission checks

  Also includes:
  - Git templates for commits, branches, PRs (separation of concerns)
  - Updated blueprints with project/workspace tools documentation
  - Updated RAG docs with project tools reference
This commit is contained in:
Renn F
2026-01-07 22:45:42 +01:00
parent 363ab6c0ce
commit f1c5b7958c
42 changed files with 2967 additions and 493 deletions
+16 -9
View File
@@ -55,17 +55,24 @@ ROBOCO_WORKSPACE_CLONE_TIMEOUT=300
3. **Branch Flexibility**: Different branches simultaneously
4. **Clean State**: Fresh clone if needed
## Workspace Resolution
## MCP Tools
When agent needs workspace:
| Tool | Purpose |
|------|---------|
| `roboco_workspace_ensure` | Create workspace if needed |
| `roboco_workspace_status` | Check workspace state |
| `roboco_workspace_list` | List all workspaces (PM only) |
```python
# Service resolves path
workspace_path = await workspace_service.get_workspace(
project_slug="roboco",
agent_id="be-dev-1"
)
# Returns: /data/workspaces/roboco/backend/be-dev-1
# Ensure workspace exists (auto-clones if needed)
roboco_workspace_ensure(project_slug="roboco")
# Check status
roboco_workspace_status(project_slug="roboco")
```
If `auto_clone=True` and workspace doesn't exist, it's created automatically.
## Workspace Resolution
Path resolved automatically: `{workspaces_root}/{project}/{team}/{agent}/`
If `auto_clone=True` and workspace doesn't exist, it's created on first access.