14:02:31ingeststep.startclassify ticket TCK-1

Governance

Permissions

Which role can run which tool action. Every cell is a live Cedar decision from the policies the agent enforces, evaluated through agent-shield, not a hand-drawn grid.

Tool actionSupportLeadEngineer
zendesk · Ticket
listTickets01—
getTicket01—
replyInternal01—
closeTicket01—
replyPublic08—
deleteUser0606
notion · KBPage
search02—
getPage02—
hubspot · Account
getAccount03—
listContacts03—
deleteAccount0606
github · Repo
createIssue—04
updateIssue—04
listProjects—04
allowconditional: permitted only when the policy condition holdsdenynumber = deciding policy · hover a cell for the ASI mapping