Capability grants
Gatekeepers
Safer than ambient MCP. Note a connector, simulate what the agent would do, then approve or deny. Real OAuth can stay noted until it is wired. Live MCP servers still belong in Vault.
No pending approvals
- What this is
- When the agent wants a side effect, the Gatekeeper simulates it here first.
- Why you need it
- You should not have to watch the chat to keep GitHub or mail safe.
- What to do next
- Connect a vendor below and run a simulation.
GitHub
Repos, issues, and pull requests the agent can act on — never the whole account.
- List issues (read)
- Open a PR (write, approval)
- Comment (write, approval)
Real GitHub OAuth is not wired on this Worker. Connect notes the grant. MCP URLs still go in Vault.
Google
Docs and Calendar, scoped to what you introduce.
- Read a Doc
- Draft an edit (approval)
- Check Calendar (read)
Google OAuth is not wired. Simulation shows the grant. Nothing leaves this vault.
Email
Draft and send from a workspace, with approval.
- Draft a reply
- Send mail (write, approval)
Outbound mail for gadgets is not connected. Sign-in mail stays on Cloudflare Email Sending.
X
Read a timeline or draft a post. Nothing posts until you approve.
- Read a timeline
- Draft a post (approval)
X OAuth is not wired. Drafts stay in this OS until a real Gatekeeper exists.
Slack
Channels you introduce, not the whole workspace.
- Read a channel
- Post a message (approval)
Slack OAuth is not wired. Use Vault MCP if you already have a Slack MCP server.
Notion
Pages and databases you pick, one at a time.
- Read a page
- Update a page (approval)
Notion OAuth is not wired. Simulation only.
Linear
Issues and projects the agent can list or update.
- List issues
- Update status (approval)
Linear OAuth is not wired. Simulation only.
Supabase
A project you introduce for app gadgets.
- Read a table
- Insert a row (approval)
Supabase is not wired. Gadgets persist in this D1 vault instead.
Durable Object Gatekeepers on the workshop Worker stay at workshop.epictechai.app. This page does not deploy over that Worker.