-
Notifications
You must be signed in to change notification settings - Fork 3
plat 541
github-actions[bot] edited this page Oct 5, 2026
·
2 revisions
State: on main, not deployed. P2.
Decision (owner, 2026-10-05): Vault (mcp-gateway) and Brain (knowledgebase) are always on, like Crew and Code, in every installation including local. Only accounts and roles change who can do what.
Done:
-
productEnabledreturns true for both whateverAGENT_PRODUCTSlists (cmd/server/server.go,coreProducts). The default frontend surfaces now includemcp-gateway. - Every active account may connect to Brain through the MCP and local tokens (
knowledgebaseMCPAllowed); the app tab needs theknowledgebaseproduct on the account (administrators have it). Agents running as a person may use Brain tools within their folder roles and a bound folder, without the app product (knowledgebaseExecute). - Content is never opened by this: administrators are Owner of every folder; everyone else sees nothing until a folder grant exists. There is no all-members grant (owner decision).
- RTS, Confida and the Excellence product list
knowledgebasein their service and frontend lists (RTS deploy guards updated). - One test pins the MCP/app split; the product-enabled test and two older tests were updated to the core rule.
Exempt (owner, 2026-10-05): SparkQuill and Dominion are their own products: a deployment whose AGENT_PRODUCTS lists sparkquill or dominion keeps its allowlist and does not get Vault or Brain.
Left: deploy RTS and verify live (consent screen for a non-admin, the tab for an account with the product, an agent run with a bound folder).
Auto-synced from docs/ on main. Edit there, not here.