System
Control
Zero-trust guardrails. Approvals, policies, autonomy and an emergency stop — nothing risky executes without passing here.
Approvals waiting · 3
terraform apply — landing zone (42 resources)
Requested by Forge · Creates production network and IAM resources.
Confirm 2 security findings before ranking
Requested by Sentry · Findings have confidence below 0.8.
Grant iam:PassRole to platform-deployer
Requested by Forge · Required for EKS node group creation.
Autonomy level
Low-risk changes run; medium and high need approval.
Policies
Human approval for production writes
Any mutating action in a production account pauses for approval.
Read-only by default
New missions start with a read-only execution identity.
Block secrets in outputs
Redact credentials from logs, chat and artifacts.
Spend cap per mission
Pause a mission that exceeds its model budget.
Off-peak changes only
Schedule high-risk changes in 02:00–04:00 UTC windows.
