Skip to content
Toggle navigation
Toggle navigation
This project
Loading...
Sign in
Ean Schuessler
/
mo-mcp
Go to a project
Toggle navigation
Toggle navigation pinning
Projects
Groups
Snippets
Help
Project
Activity
Repository
Graphs
Issues
0
Merge Requests
0
Wiki
Network
Create a new issue
Commits
Issue Boards
Files
Commits
Network
Compare
Branches
Tags
2e5c8995
authored
2025-12-11 22:11:13 -0600
by
Ean Schuessler
Browse Files
Options
Browse Files
Tag
Download
Email Patches
Plain Diff
Fix security model: plugin uses ADMIN for discovery, enforces user permissions -…
… deterministic and secure
1 parent
aeecc016
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
12 additions
and
12 deletions
README.md
README.md
View file @
2e5c899
...
...
@@ -37,23 +37,23 @@ Foundation for autonomous business operations (ECA/SECA systems).
**⚠️ CONTAINERS & SECURITY REQUIRED ⚠️**
## 🛡️ **Security:
AI User Avatars
**
## 🛡️ **Security:
Deterministic by Design
**
AI agents authenticate as
**Moqui users**
with
**role-based permissions**
- same security as human employees.
**Plugin uses ADMIN context for discovery, enforces user permissions for access.**
### **
Safe Privilege Escalation
**
-
**
Start Limited**
: AI begins with basic permissions (read-only catalog access)
-
**
Earn Trust**
: Proven performance triggers Moqui status transition
s
-
**
Role Progression**
: AI "promotes" from trainee → specialist → manage
r
-
**
Business Rules**
: All actions constrained by Moqui's compliance framework
### **
How It Works
**
-
**
Discovery Phase**
: Plugin uses ADMIN context to find all available screens
-
**
Permission Check**
: User permissions enforced before any screen acces
s
-
**
No Escalation**
: Users can only access screens they're authorized fo
r
-
**
Deterministic**
: Predictable security boundaries, no privilege bypass
### **
Built-In Safety
**
-
**
Audit Trails**
: Every AI action logged and reversible
-
**
Financial Limits**
: Can't exceed authorized spending threshold
s
-
**
Multi-Approval**
: Critical decisions require human supervisor
### **
Security Model
**
-
**
Complete Discovery**
: See all screens that exist in the system
-
**
User Enforcement**
: Access limited to user's actual permission
s
-
**
Audit Safe**
: All actions logged and traceable to real users
-
**Container Isolation**
: Run in Docker/Kubernetes with separate databases
**Result**
:
AI agents follow same career progression and safety protocols as human employees
.
**Result**
:
Elegant design - discover everything, enforce user permissions strictly
.
## Overview
...
...
Please
register
or
sign in
to post a comment