Skip to content
DocsOwnership and guardrails

Ownership and guardrails

Declared paths, action grants, check, and the shared-checkout contract every crew carries.

Crew share one checkout. Nothing locks a file, so the whole safety story is declared ownership, action grants, and a contract every captain and crew carries in its instructions.

Declaring ownership#

--owns PATH records a path as belonging to one assignment. Repeat it per path. Overlapping active ownership between crew is refused, which is what keeps two simultaneous writers off the same file.

shell
captain crew Gibbs --task "Rewrite the docs content" \
  --owns src/content --owns src/app/docs --allow edit

Action grants#

read and search are always granted. Everything else is opt-in with --allow ACTION, repeated as needed.

Grantable actions
ActionNotes
readAlways granted.
searchAlways granted.
editRequires owned paths.
test
build
formatNever repo-wide. Own files only.
commitOnly when you explicitly asked for a commit.
versionOnly when you explicitly asked for a bump.
deleteRequires owned paths.

Checking a grant#

check answers whether an action on given paths is permitted. It executes nothing — it is a question, not a gate in front of a tool.

shell
captain check Jack edit src/example.py
json
{"assignment_id": "fb7fd383...", "allowed": true}

A mutation action is refused when the assignment declares no owned paths covering them. Protocol commands validate themselves, so only filesystem and work actions need a check.

The shared-checkout contract#

Both captain and crew instructions carry the same rules, because a shared checkout fails in the same way from either side.

  • Edit only files in your own assignment. Give simultaneous writers disjoint files, and serialise same-file work.
  • Re-read a file right before editing it, and keep others' unexpected changes in place.
  • Stage and commit only your own files and hunks. Never git add -A, never repo-wide formatting.
  • Never overwrite, rewrite from scratch, or discard existing or uncommitted work. Edit in place, and ask the user first if an assignment implies replacing content.
  • Finish, or record a handoff, before anyone else edits your file.
  • Never commit or bump the version unless the user explicitly asks. Otherwise leave the work in the tree and report the diff.

What this is not#

Bounded inspection is the safe read path. See when to recruit for captain inspect and its limits.