Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Mahmoud Mabrouk seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. You have signed the CLA already but the status is still pending? Let us recheck it. |
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Agenta mirrors Workspace members into Projects, and Project roles control access by resource type. Any member with
view_sessionscan read every session in the Project. The UI never shows that audience, and a user cannot start personal work and later share it with one colleague. That fits shared traces, evaluations, and testsets. It does not fit interactive agent sessions, which look like personal conversations.This PR adds the design workspace for a team collaboration foundation. It is documentation only. No code changes, no implementation started.
What is in
docs/design/team-collaboration/README.mdindexes the set and defines the glossary (Workspace, Project, session access record, audience, grant, View vs Join). It states the design rule: no generic ACL framework yet.prd.mdis the foundation PRD. Three tracks: authorization consistency, session audiences, session sharing.rfc-0-authorization-consistency.mdfixes the current gaps first: Project mutations lack role checks, generic role assignment can grant Owner, member removal does not revoke personal API keys, and Viewer can decrypt secrets.rfc-1-session-audiences.mdadds a server-filtered "My sessions" view, then personal vs Project audiences enforced through one session access record.rfc-2-session-sharing.mdadds named read access, Project sharing, revocation, and owner lifecycle. Join, groups, and public links are out of scope.research.mdcompares three anonymized competitors with Agenta on sharing, visibility, roles, ownership, and governance, with a provisional Kano analysis.status.mdtracks state and the open decisions.walkthrough.htmlis an interactive step-through of the research, the direction, and the three RFCs. Open it in a browser.Status
Research and first PRD/RFC drafts are complete. Nothing is implemented.
status.mdlists seven product decisions that must be settled before implementation, and names the first safe slice: the server-filtered "My sessions" view, which ships without authorization changes.Review wanted
Product direction and the seven decisions in
status.md. Not the prose.https://claude.ai/code/session_01UcHDEJ93d5idwAhMCTf4a4