Security

Control the authority around the agent.

Scylla applies policy before consequential operations reach files, Git, databases, shells, MCP tools, and brokered external systems.

Define what Scylla is allowed to do, once.

Git, Filesystem, Database, Shell / SSH, and MCP share one authority model.

Policy inheritance

Lower scopes may become more restrictive. They cannot weaken an enforced parent rule.

Scylla Hard Rules
Organization
User Tightening
Project / Connection
OperationAllowAskBlock
Git status
Git push
Force push
Project read
Project delete
Outside-project

Broker & Keyring

Give agents capabilities, not credentials.

The Broker evaluates policy, resolves Keyring secrets internally, and executes approved operations. The agent receives the result — not the reusable secret.

Broker

Policy-gated execution for database, shell, and external connections.

Keyring

Protected secrets stay in the local Keyring — outside agent context.

Native backstops

OS and platform permission prompts remain in place where the host requires them.

Team Policy

Managed Global Policy for organizations.

Team admins publish an organization baseline. Members may tighten locally. Enforced rules cannot be weakened.