Create policy
Create tool permission
Policies
Select a principal to view or create policies.
Tool permissions
Select a policy to inspect current tool permissions.
Tool catalog
Tap a tool to prefill the permission form with a governed target.
systems � Append an operational note to a system.
deployments � Approve a pending deployment.
systems � Assign an owner or operator to a system.
systems � Add a container record to a system.
systems � Add a service endpoint to a container.
systems � Create a new system inventory record.
knowledge � Create a commit/push job for pending wiki edits.
knowledge � Execute a pending wiki commit job immediately.
control-room � Fetch the current Control Room overview snapshot.
deployments � Fetch a single deployment record.
systems � Read the full inventory record for a system.
knowledge � Read the status of a wiki commit job.
costs � Force a Hetzner cost recalculation for the selected scope.
costs � List estimated Hetzner cost line items by resource.
costs � Read the current estimated Hetzner 30-day cost summary.
costs � Read the daily Hetzner cost trend series.
costs � Import or replace the active Hetzner pricing map.
operations � Create or repair the managed Hetzner private network, subnet, firewall, and generated GitHub Actions secrets for an environment.
operations � End an active host repair session.
operations � Execute an approved host repair command within an active session.
operations � Read bounded service, container, or file logs within an active host repair session.
operations � Start an ephemeral host repair session for a specific environment.
sources � Index repository content for search and knowledge discovery.
knowledge � Create an intake draft under /drafts and prepare ranked merge targets.
knowledge � Read a wiki draft intake record.
knowledge � Accept a draft merge preview and write a new revision to the target page.
knowledge � Generate a reviewable merge preview for a selected target page.
knowledge � Reject a draft merge preview without modifying the target page.
knowledge � List ranked target-page suggestions for a draft intake.
knowledge � Select a target page for a wiki draft intake.
knowledge � List the wiki hierarchy for manual target selection.
sources � List tracked repository mirrors and sync/index status.
deployments � List recent deployments for a service.
systems � List active systems in the Control Room inventory.
knowledge � List recent wiki commit jobs for a repository.
migrations � Start a discovery run for a migration project.
migrations � Request or perform migration cutover after required validation gates pass.
migrations � Read a migration execution with step and validation state.
migrations � Request or perform rollback for a migration execution.
migrations � Start a governed migration execution from an approved migration plan.
migrations � Run or refresh validation gates for a migration execution.
migrations � Read a migration project and its target profile.
migrations � List migration projects and their current states.
migrations � Generate a migration plan with validation and rollback checkpoints.
migrations � Read a generated migration plan with ordered steps and environment mappings.
knowledge � Read a wiki or markdown document from a mirrored repository.
operations � Refresh REGISTRY_URL and REGISTRY_USERNAME for a GitHub environment. GHCR deployments use the GitHub Actions GITHUB_TOKEN.
deployments � Reject a pending deployment.
deployments � Create an approval request for a deployment.
deployments � Request a rollback to an earlier deployment.
knowledge � Search indexed markdown and code content across configured repositories.
sources � Run repository synchronization against origin.
systems � Trigger a new Windows golden image build run.
systems � Get a Windows image build run.
systems � Create a Windows golden image family for Hetzner automation.
systems � List Windows golden image families through the image catalog.
systems � Approve a Windows image version for deployment.
systems � Deprecate a Windows image version.
systems � Get a Windows image version with build lineage and linked servers.
systems � List Windows image versions with approval and lifecycle state.
systems � Reject a Windows image version.
systems � Mark an approved Windows image version as the default deployment image.
systems � Deploy a managed Windows server from an approved image.
systems � Get a managed Windows server with provisioning details.
systems � List managed Windows servers deployed from golden images.
knowledge � Update markdown content in a controlled wiki repository.
systems � Update an existing system inventory record.
knowledge � Append to the Developer diary, creating the day page when needed.
knowledge � Append a timestamped note to an existing wiki page and create a revision.
sources � Register a Git repository and one or more mirror profiles for mirrored wiki content.
knowledge � Search wiki pages with unified ranking across native, seeded, and mirrored content, including source labels and optional filters.
sources � Sync a registered repository and refresh mirrored wiki pages and search results.
systems � Create a disposable Windows VM and return a one-time Administrator password.
systems � Delete a disposable Windows VM instance.
systems � List disposable Windows VM instances.
systems � Recreate a disposable Windows VM with a new one-time Administrator password.