The two rights
Reading a Brain — browsing rules, the graph, history, and asking it questions — needs only
View Brains.
Two typical roles
- Approver — Edit Brains + Approve Brain Rules. Domain owners and ops leads who decide what the agents follow.
- Contributor — Edit Brains only. Analysts and subject-matter experts who propose rules.
Everything they add waits in Needs review until an approver puts it into force; the approve,
retire and restore controls are not shown to them, and the API answers
403if called directly.
What changes for existing accounts
Nothing, until you decide it should. Every role that could edit rules before this permission existed was granted Approve Brain Rules automatically. To create a contributor role, edit the role and untick Approve Brain Rules.Approving your own draft
Allowed. Approval is a right, not a second pair of eyes — an approver who drafts a rule can put it into force in the same sitting.Auto-approval
Two features file rules into the graph without a per-rule click, and both are approver-only:- “Approve automatically” on an import, upload or repository build. Without the approve right the request is refused rather than quietly downgraded, so a script is never told its rules went live when they did not.
- Auto-approve recurring rules in the Brain’s Settings, which lets a draft that keeps being proposed from real tasks approve itself. Only an approver can turn it on or off.
Agents and Brains
An agent reads the one Brain configured in its settings. Theget_brain_context tool follows
the same rule: with a Brain configured, it only ever consults that Brain.