Files
roboco/docs/rag/architecture/tool-permissions.md
T
Renn F f1c5b7958c Add Project & Workspace MCP System with role-based permissions
- Add roboco_project_* tools (list, get, create, update) with CEO bypass
  - Add roboco_workspace_* tools (ensure, status, list) for workspace management
  - Add project_slug and requires_git fields to TaskCreateInput schema
  - Validate project exists and cell matches when creating git-enabled tasks
  - Register project MCP server in orchestrator with proper permissions

  Workspace permissions by role:
  - Developer: Write to own workspace only
  - QA: Read-only access to all cell workspaces
  - Documenter: Write to all cell workspaces (add docs to dev branches)
  - Cell PM: Write to own workspace, project_update for own cell
  - Main PM: Full project access (create, update all, workspace_list all)
  - CEO: Full bypass on all permission checks

  Also includes:
  - Git templates for commits, branches, PRs (separation of concerns)
  - Updated blueprints with project/workspace tools documentation
  - Updated RAG docs with project tools reference
2026-01-07 22:45:42 +01:00

2.1 KiB

Tool Permissions by Role

Overview

Agents have role-specific tool permissions enforced via Claude Code settings. Native tools are blocked; use roboco_* MCP tools instead.

Developer

Allowed:

  • roboco_task_* - task lifecycle
  • roboco_git_* - all git operations
  • roboco_test_* - run tests, lint, format
  • roboco_journal_* - journaling
  • roboco_kb_*, roboco_rag_* - knowledge base
  • Read(*) - read any file
  • Write/Edit - workspace only

Blocked:

  • Bash(git:*) - use roboco_git_* instead
  • Write/Edit outside workspace

Workspace: /data/workspaces/{project}/{team}/{agent-id}/

QA

Allowed:

  • roboco_git_status, roboco_git_log, roboco_git_diff - read-only
  • roboco_test_* - run tests
  • roboco_task_qa_pass, roboco_task_qa_fail
  • Read(*) - read any file

Blocked:

  • roboco_git_commit, roboco_git_push - QA doesn't write code
  • All Write/Edit - review only

Documenter

Allowed:

  • roboco_docs_* - documentation tools
  • roboco_git_* - all git operations
  • Write/Edit in /app/docs/** only

Blocked:

  • Write/Edit outside docs directory

PM (Cell PM, Main PM)

Allowed:

  • roboco_git_* - all git operations
  • roboco_docs_* - documentation
  • roboco_task_* - full task management
  • roboco_notify_send - send notifications

Blocked:

  • Bash(git:*) - use roboco_git_*

Auditor

Allowed:

  • roboco_git_status, roboco_git_log, roboco_git_diff - read-only
  • Read(*) - read any file

Blocked:

  • All write operations - observer role

Project Tools

Tool Dev/QA/Doc Cell PM Main PM CEO
roboco_project_list Own cell Own cell All All
roboco_project_get Yes Yes Yes Yes
roboco_project_create No No Yes Yes
roboco_project_update No Own cell All All
roboco_workspace_ensure Yes Yes Yes Yes
roboco_workspace_status Yes Yes Yes Yes
roboco_workspace_list No Own cell All All

CEO Bypass: CEO has full access to all project operations.