Agent Permission Explorer

Model what an AI agent can read, write, administer, or chain together across repositories, CI/CD, terminals, secrets, cloud, production, email, browser sessions, and SaaS tools.

25%
Bounded starting point

The modeled access looks more contained. Keep reviewing tool behavior, data exposure, and escalation paths.

1. What can the agent access?

RepositoriesSource code, pull requests, branches, issues, and release metadata.
CI/CDBuild workflows, deployment jobs, artifacts, runners, and pipeline secrets.
TerminalShell commands, package managers, local files, scripts, and test runners.
SecretsAPI keys, environment variables, vault entries, tokens, and certificates.
CloudAWS, Azure, GCP, IAM, storage, logs, workloads, and network controls.
ProductionCustomer-facing systems, runtime configuration, firewall rules, and data stores.
EmailMailbox content, attachments, calendar context, and outbound messages.
BrowserWeb sessions, SaaS dashboards, forms, downloads, and untrusted pages.
SaaS toolsJira, Slack, Google Workspace, ticketing, CRM, docs, and admin panels.

2. Which controls already exist?

3. Reachability paths

No obvious multi-system chain path detected from these selections. Still review the actual tools, logs, network access, and data sources.

Use the report before approving a new agent workflow.

Run the explorer during design review, paste the result into a PR or ticket, then verify that high-impact actions have scoped identity, approval, logging, revocation, and isolation before launch.