mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
- Add roboco_project_* tools (list, get, create, update) with CEO bypass - Add roboco_workspace_* tools (ensure, status, list) for workspace management - Add project_slug and requires_git fields to TaskCreateInput schema - Validate project exists and cell matches when creating git-enabled tasks - Register project MCP server in orchestrator with proper permissions Workspace permissions by role: - Developer: Write to own workspace only - QA: Read-only access to all cell workspaces - Documenter: Write to all cell workspaces (add docs to dev branches) - Cell PM: Write to own workspace, project_update for own cell - Main PM: Full project access (create, update all, workspace_list all) - CEO: Full bypass on all permission checks Also includes: - Git templates for commits, branches, PRs (separation of concerns) - Updated blueprints with project/workspace tools documentation - Updated RAG docs with project tools reference
2.1 KiB
2.1 KiB
Tool Permissions by Role
Overview
Agents have role-specific tool permissions enforced via Claude Code settings.
Native tools are blocked; use roboco_* MCP tools instead.
Developer
Allowed:
roboco_task_*- task lifecycleroboco_git_*- all git operationsroboco_test_*- run tests, lint, formatroboco_journal_*- journalingroboco_kb_*,roboco_rag_*- knowledge baseRead(*)- read any fileWrite/Edit- workspace only
Blocked:
Bash(git:*)- use roboco_git_* insteadWrite/Editoutside workspace
Workspace: /data/workspaces/{project}/{team}/{agent-id}/
QA
Allowed:
roboco_git_status,roboco_git_log,roboco_git_diff- read-onlyroboco_test_*- run testsroboco_task_qa_pass,roboco_task_qa_failRead(*)- read any file
Blocked:
roboco_git_commit,roboco_git_push- QA doesn't write code- All
Write/Edit- review only
Documenter
Allowed:
roboco_docs_*- documentation toolsroboco_git_*- all git operationsWrite/Editin/app/docs/**only
Blocked:
Write/Editoutside docs directory
PM (Cell PM, Main PM)
Allowed:
roboco_git_*- all git operationsroboco_docs_*- documentationroboco_task_*- full task managementroboco_notify_send- send notifications
Blocked:
Bash(git:*)- use roboco_git_*
Auditor
Allowed:
roboco_git_status,roboco_git_log,roboco_git_diff- read-onlyRead(*)- read any file
Blocked:
- All write operations - observer role
Project Tools
| Tool | Dev/QA/Doc | Cell PM | Main PM | CEO |
|---|---|---|---|---|
roboco_project_list |
Own cell | Own cell | All | All |
roboco_project_get |
Yes | Yes | Yes | Yes |
roboco_project_create |
No | No | Yes | Yes |
roboco_project_update |
No | Own cell | All | All |
roboco_workspace_ensure |
Yes | Yes | Yes | Yes |
roboco_workspace_status |
Yes | Yes | Yes | Yes |
roboco_workspace_list |
No | Own cell | All | All |
CEO Bypass: CEO has full access to all project operations.