- What: which driver, which model, with which arguments.
- Where: the assigned roost.
- How long: TTL.
- Which tools: capability-scoped allowlist for
/v1/toolcalls.
Why it matters
- Denied by default. Without a grant, no agent runs. Without a matching tool capability, no tool fires.
- Verifiable. Every line of the audit log can be replayed against the gateway’s public key.
- No amplification. A grant cannot be re-delegated more powerfully than its parent.