Alpha Omega / Trust center
Tool permissions
Capabilities are default-deny, scoped, visible, and revocable.
Approval
An approval explains the requested capability, why it is needed, the data and domains involved, whether it has external side effects, how long it lasts, and how to revoke it.
Risk levels
Low-risk schema and local transforms may be automatically allowed by policy. Medium-risk external access requires explicit installation approval. High-risk external side effects require stronger approval and normally a decision for every invocation.
Revocation
Disabling or uninstalling a tool stops later invocations. Revoked permission rows remain part of the audit and version history.