mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
- Add roboco_project_* tools (list, get, create, update) with CEO bypass - Add roboco_workspace_* tools (ensure, status, list) for workspace management - Add project_slug and requires_git fields to TaskCreateInput schema - Validate project exists and cell matches when creating git-enabled tasks - Register project MCP server in orchestrator with proper permissions Workspace permissions by role: - Developer: Write to own workspace only - QA: Read-only access to all cell workspaces - Documenter: Write to all cell workspaces (add docs to dev branches) - Cell PM: Write to own workspace, project_update for own cell - Main PM: Full project access (create, update all, workspace_list all) - CEO: Full bypass on all permission checks Also includes: - Git templates for commits, branches, PRs (separation of concerns) - Updated blueprints with project/workspace tools documentation - Updated RAG docs with project tools reference
80 lines
2.1 KiB
Markdown
80 lines
2.1 KiB
Markdown
# Tool Permissions by Role
|
|
|
|
## Overview
|
|
|
|
Agents have role-specific tool permissions enforced via Claude Code settings.
|
|
Native tools are blocked; use `roboco_*` MCP tools instead.
|
|
|
|
## Developer
|
|
|
|
**Allowed:**
|
|
- `roboco_task_*` - task lifecycle
|
|
- `roboco_git_*` - all git operations
|
|
- `roboco_test_*` - run tests, lint, format
|
|
- `roboco_journal_*` - journaling
|
|
- `roboco_kb_*`, `roboco_rag_*` - knowledge base
|
|
- `Read(*)` - read any file
|
|
- `Write/Edit` - workspace only
|
|
|
|
**Blocked:**
|
|
- `Bash(git:*)` - use roboco_git_* instead
|
|
- `Write/Edit` outside workspace
|
|
|
|
**Workspace:** `/data/workspaces/{project}/{team}/{agent-id}/`
|
|
|
|
## QA
|
|
|
|
**Allowed:**
|
|
- `roboco_git_status`, `roboco_git_log`, `roboco_git_diff` - read-only
|
|
- `roboco_test_*` - run tests
|
|
- `roboco_task_qa_pass`, `roboco_task_qa_fail`
|
|
- `Read(*)` - read any file
|
|
|
|
**Blocked:**
|
|
- `roboco_git_commit`, `roboco_git_push` - QA doesn't write code
|
|
- All `Write/Edit` - review only
|
|
|
|
## Documenter
|
|
|
|
**Allowed:**
|
|
- `roboco_docs_*` - documentation tools
|
|
- `roboco_git_*` - all git operations
|
|
- `Write/Edit` in `/app/docs/**` only
|
|
|
|
**Blocked:**
|
|
- `Write/Edit` outside docs directory
|
|
|
|
## PM (Cell PM, Main PM)
|
|
|
|
**Allowed:**
|
|
- `roboco_git_*` - all git operations
|
|
- `roboco_docs_*` - documentation
|
|
- `roboco_task_*` - full task management
|
|
- `roboco_notify_send` - send notifications
|
|
|
|
**Blocked:**
|
|
- `Bash(git:*)` - use roboco_git_*
|
|
|
|
## Auditor
|
|
|
|
**Allowed:**
|
|
- `roboco_git_status`, `roboco_git_log`, `roboco_git_diff` - read-only
|
|
- `Read(*)` - read any file
|
|
|
|
**Blocked:**
|
|
- All write operations - observer role
|
|
|
|
## Project Tools
|
|
|
|
| Tool | Dev/QA/Doc | Cell PM | Main PM | CEO |
|
|
|------|------------|---------|---------|-----|
|
|
| `roboco_project_list` | Own cell | Own cell | All | All |
|
|
| `roboco_project_get` | Yes | Yes | Yes | Yes |
|
|
| `roboco_project_create` | No | No | Yes | Yes |
|
|
| `roboco_project_update` | No | Own cell | All | All |
|
|
| `roboco_workspace_ensure` | Yes | Yes | Yes | Yes |
|
|
| `roboco_workspace_status` | Yes | Yes | Yes | Yes |
|
|
| `roboco_workspace_list` | No | Own cell | All | All |
|
|
|
|
**CEO Bypass:** CEO has full access to all project operations.
|