Skip to content

Security review

llms.txtlists every page for an agent

What each job can reach and who can approve, with the record every change leaves.

Works

  • Plan and apply use separate roles, and the plan job never gets the apply role
  • A gated wave whose plans moved after the approval applies nothing and names both digests
  • The audit trail in your bucket records every approval, apply and override

Differs

  • terragucci has no accounts; access and identity maps each action to the forge or IAM setting that decides it.

First step

The threat model

You can count on

Then read

Tasks
Write a policyRead the audit trailLock rootsSecrets out of notesScope state accessApprovals runbook
Background
Approvals as recordsAccess and identity
Details
Threat modelPolicyThe audit trailValidation

terragucci

These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.