Read-only should be a permission. Not a request.
A coding assistant investigates a production problem but attempts a destructive database operation during diagnosis.
All use casesMake the boundary explicit.
Separate development and production credentials. Grant read-only diagnostics, expose permitted typed operations and enforce policy at the executor. Restrict shell access so it cannot bypass the protected path.
Approved log reads succeed. Destructive production mutation is denied before dispatch instead of merely discouraged in a prompt.
Inspect the decision.
Read approved production diagnostic logs.
Ready to evaluate
No external action
Select a variation and inspect the local example. This demonstration does not call a model or connect to a business system.
Database permissions and backups remain separate controls. An unmediated administrator credential would bypass this boundary.
The controls behind the workflow.
Explore the capabilities that compose around this task, rather than treating each step as a separate product.
Related ways to use DriftGate.
A working environment should travel. Credentials should not.
A developer joins a payments project while also working on a public marketing website. The projects need different tools, instructions, accounts and restrictions.
Review the update before it changes your agents’ permissions.
A previously approved MCP or skill release adds a tool, broadens network access or changes its instructions.