Permission model01 02 03 04 05
Permission model
/docs/permissions
Standard / Full Access — real labels in the composer.
Rule 1
Low-risk Skills can auto-execute when policy allows
Rule 2
Medium/high-risk Skills require explicit confirmation unless a matching Full Access grant exists for the current task
Rule 3
Full Access is current-task scoped, is current-task scoped and bounded by configured scope
Rule 4
Runtime still enforces: availability / implementation / dependency / scope / sandbox
Rule 5
All decisions go into JSONL audit