Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260831-2104-tyrell-agent-permission-audit

rdmsm4x — Tyrell agent permission audit (EPIC-20260831-03)

Session: 2026-08-31 20:53 → 21:10 EDT (rdmsm4x, macOS 27.0, arm64) Project: ~/dev/apps/tyrell · Follows: SEC-20260831-09 / ~/dev/fleet/tcc-privileges

Built the agent-permission audit into Tyrell and filed the epic that tracks the rest. Tyrell now answers a question nothing on the fleet could answer: do the agent CLIs, terminal apps and sshd on this Mac actually hold Screen Recording, Full Disk Access and Accessibility — and is each grant still attached to the binary running right now.

Tickets filed

Ticket State
EPIC-20260831-03 — agent permission audit open (parent)
FEAT-20260831-09 — pure model, parsing, orphan detection resolved
FEAT-20260831-10 — read-only collector, live-binary resolution resolved
FEAT-20260831-11 — CLI subcommand + MCP tool in progress (MCP done, CLI blocked)
UI-20260831-02 — app panel open
FEAT-20260831-12 — fleet aggregation open
FEAT-20260831-13 — alert on upgrade-orphaned grants open
ISSUE-20260831-20 — another session's SQLITE_BUSY regression, routed not absorbed open

Files changed — all in ~/dev/apps/tyrell, none committed (see "Why nothing was committed")

Verification

Why nothing was committed

Another session (7b602c9b, active) is mid-migration off GRDB onto TyrellSQLite.swift + ecs0lib, holding uncommitted changes to Package.swift, SQLiteStateStore*.swift, StoreRefs.swift, Sources/tyrell/Tyrell.swift (627 lines), ChatRoutes.swift, Daemon.swift and ChatAuthorityTests.swift. My one-line Package.swift change lands in the same diff hunk as their GRDB dependency removal: committing it would sweep their whole migration into my commit, and committing the sources without it would leave HEAD unbuildable. Left in the working tree with the handoff written into Tyrell's SESSION-STATE.md §5.

For the same reason there is no tyrell agent-permissions subcommand yet — registering one means editing Tyrell.swift while it is being rewritten. The MCP tool gives agents the same answer with no collision.

Notable

Undo

Remove the three new files, revert the one exclude: line in Package.swift and the agent_permissions additions in MCPMain.swift. Nothing is committed, installed, signed or deployed. No secrets read or written; every TCC access was read-only.