Permissions
✓ granted · ✓* granted by wildcard · ✕ explicitly denied · · not granted.
Derived from profiles/profiles.yaml on every request — never stored.
| role | context | technical-design | product-intent | creative-intent | creative-direction | outline | slice | brand-and-legal | publish | merge | sensitive-path | tiers |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| owner | ✓* | ✓* | ✓* | ✓* | ✓* | ✓* | ✓* | ✓* | ✓* | ✓* | ✓* | * |
| engineer | ✓ | ✕ | · | · | · | ✓ | ✓ | · | · | ✕ | ✕ | T0, T1, T2, T3 |
| contributor | · | · | · | · | · | · | ✓ | · | · | · | · | T1, T2, T3 |
| operator | · | ✕ | ✓ | ✓ | · | · | ✕ | · | · | ✕ | ✕ | * |
| client | · | · | ✓ | · | · | · | · | · | · | · | · | |
| agent_scout | · | · | · | · | · | · | · | · | · | · | · | T0, T1, T2, T3 |
| agent_builder | · | · | · | · | · | · | · | · | · | · | · | T0, T1, T2, T3 |
| agent_ci | · | · | · | · | · | · | · | · | · | · | · | |
| agent_untrusted | · | · | · | · | · | · | · | · | · | · | · |
Findings (10)
sole-approver
T0 — at T0, only "owner" may approve "merge"sole-approver
T0 — at T0, only "owner" may approve "technical-design"sole-approver
T1 — at T1, only "owner" may approve "merge"sole-approver
T1 — at T1, only "owner" may approve "sensitive-path"sole-approver
T1 — at T1, only "owner" may approve "technical-design"sole-approver
T2 — at T2, only "owner" may approve "merge"sole-approver
T2 — at T2, only "owner" may approve "sensitive-path"dead-grant — owner may approve "context", but no tier owner works at emits that gate kind
dead-grant — engineer may approve "context", but no tier engineer works at emits that gate kind
dead-grant — contributor may approve "slice", but no tier contributor works at emits that gate kind