Agent-User
Permission model

Permission model

/docs/permissions

Standard / Full Access — real labels in the composer.

01

Rule 1

Low-risk Skills can auto-execute when policy allows

02

Rule 2

Medium/high-risk Skills require explicit confirmation unless a matching Full Access grant exists for the current task

03

Rule 3

Full Access is current-task scoped, is current-task scoped and bounded by configured scope

04

Rule 4

Runtime still enforces: availability / implementation / dependency / scope / sandbox

05

Rule 5

All decisions go into JSONL audit