Permissions and Safe Operations
Capability gates
| Operation | Current policy |
|---|---|
| Documentation guidance, CLI discovery, and local version check | Enabled |
whoami and the four workflow Read allowlists | Enabled |
| Deployment, Dataset Preparation, and Evaluation Preview | Enabled |
| Deployment Create, bounded waiter, and result verification | Enabled |
| Training Preview; Dataset Preparation, Training, and Evaluation waiter/verification | Verify before release |
| Dataset, Training, or Evaluation create/start; upload, update, stop, restart, cancel, delete | Disabled pending workflow E2E |
| API Key or Provider Key management, secret reveal, raw request or token access | Denied |
Only enabled authorizes the Skill to call an operation. The presence of an
SDK method, a Human example, or a global For Agent switch is not authorization.
For upload, create, update, stop, restart, cancel, delete, and any other
mutation, the top-level executionEnabled gate must also be true.
Write-operation confirmation
Before an enabled write, the Agent summarizes the environment, operation, target, non-secret inputs, Preview result, resource impact, expected terminal state, timeout, and verification route. A current request that explicitly asks the Agent to create or start that normalized outcome counts as execution confirmation. Ask once only when a missing or changed choice materially alters resource use, cost, or the requested result.
Required stop conditions
Stop when:
- The environment, identity, permission, version, or capability is uncertain.
- Preview says the request cannot be created or capacity is unavailable.
- A Provider Key or other secret would need to enter the prompt.
- The user rejects or changes the final plan.
- A response does not match the documented contract.
- A mutation result is unknown and there is no safe lookup or idempotency key.
- A bounded waiter reaches its timeout.
Do not bypass a stop through browser clicks, frontend internal APIs, raw HTTP, or another SDK language.
Sensitive outputs
Never return API keys, bearer tokens, Provider Keys, KubeConfig, credential files, pre-signed object URLs, Deployment YAML containing environment details, or raw secret fields.