Permissions below the model
Organization roles govern the resources and operations a person can access. The agent’s tool calls are checked against that authority. Instructions can guide behavior; they cannot grant a permission.
Give your agent the ability to operate an application, with permissions, approvals and secret access enforced by the tooling underneath it.
Explore the runtime baselineThese controls belong to the system that executes the change. They keep working when the conversation ends or a different agent takes over.
Organization roles govern the resources and operations a person can access. The agent’s tool calls are checked against that authority. Instructions can guide behavior; they cannot grant a permission.
Review the proposed deployment, affected resources, warnings and estimated costs before provisioning. Protected actions wait for a decision in Monk’s dashboard. A chat message is not a dashboard approval.
Enter credentials in Monk’s local form. Tools refer to secret names while the vault handles values. Workloads and integrations declare the secrets they may read through permitted-secrets.
Production, staging and branch environments have their own configuration and access context. Capsules can use separate clusters or share capacity. Choose separate clusters when the boundary must include the infrastructure itself.
Tool actions and approval events are attributed to an actor and recorded in the organization’s activity trail. Inspect what was requested, how it was decided and whether the action completed.
The orchestrator recovers workloads within configured policies, retry budgets and available capacity. Watcher investigates incidents and proposes repairs. Those repairs need your approval.
Your cloud account stays yours. You choose the credentials, environment boundaries and access you give Monk.
Controls for the infrastructure itself: how nodes communicate, how resources are exposed and how secrets reach their consumers.
Monk’s WireGuard overlay carries traffic between managed nodes. Declared connections give the orchestrator the information it needs to wire services across machines and clouds.
External SaaS connections use the provider’s own endpoints and transport.
Ingress and published ports determine which application endpoints are public. Internal dependencies communicate over the managed network; adding a database does not require a public application endpoint.
Review ingress, provider firewall rules and external service allowlists as part of the deployment.
The local companion uses an OS keychain or encrypted vault. The orchestrator’s vault supports envelope encryption and KMS backends for AWS, Google Cloud and Azure, alongside its local backend.
The configured backend and scope determine where a secret is stored and which workloads receive it.
Cluster peers have cryptographic identities, and the management transport uses authenticated, encrypted connections. Organization authorization controls access to managed resources.
Personal accounts and organization scopes have different access models. Cloud credentials also retain their provider-side permissions.
Tool inputs are checked against schemas. Deployment configuration is analyzed before execution, and protected operations use explicit approval flows.
Validation checks configuration and permissions; application testing remains part of your release process.
Secrets are resolved by the runtime for authorized consumers. Explicit secret declarations constrain access by workload or entity, instead of giving every component a shared credential pool.
Application code still controls what it writes to logs or sends to other services.
Monk’s local companion, your coding-agent host and your cloud have different responsibilities.
Read the privacy policyNo. Team instructions guide the agent’s choices. Organization permissions, provider credentials and tool approval checks determine what it can execute.
No. Read operations and configured workload recovery can proceed within their existing authority. Deployment plans and protected changes use the relevant approval flow. Watcher’s proposed repairs require human approval.
Capsules support both new cluster capacity and an existing shared cluster. The plan determines which services, credentials and resources are separate or shared. Choose that boundary before deploying.
Monk does not currently claim a security certification. Contact the security team for the current audit program, available evidence and your organization’s review requirements.
For architecture reviews or private vulnerability reports, contact security@monk.io. Include reproduction steps and impact when reporting a vulnerability.