Broker
Policy-gated execution for database, shell, and external connections.
Security
Scylla applies policy before consequential operations reach files, Git, databases, shells, MCP tools, and brokered external systems.
Git, Filesystem, Database, Shell / SSH, and MCP share one authority model.
Lower scopes may become more restrictive. They cannot weaken an enforced parent rule.
Broker & Keyring
The Broker evaluates policy, resolves Keyring secrets internally, and executes approved operations. The agent receives the result — not the reusable secret.
Policy-gated execution for database, shell, and external connections.
Protected secrets stay in the local Keyring — outside agent context.
OS and platform permission prompts remain in place where the host requires them.
Team Policy
Team admins publish an organization baseline. Members may tighten locally. Enforced rules cannot be weakened.