Security review
llms.txtlists every page for an agent
What each job can reach and who can approve, with the record every change leaves.
Works
- Plan and apply use separate roles, and the plan job never gets the apply role
- A gated wave whose plans moved after the approval applies nothing and names both digests
- The audit trail in your bucket records every approval, apply and override
Differs
- terragucci has no accounts; access and identity maps each action to the forge or IAM setting that decides it.
First step
You can count on
- A plan note on every pull request
- Gated applies of the plans you approved
- No overlapping or stale applies
- Re-plan from a comment
- Scheduled drift checks
- OIDC roles, one to plan, one to apply
- Policy on every plan
- An audit trail in your bucket
- Secrets kept out of notes and logs
- Your state backend, as is
- Your own runners
- Your forge's sign-in and permissions
Then read
These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.