docs: document AI Workspace Engine entitlement adapter
This commit is contained in:
@@ -155,7 +155,7 @@ Scenarios:
|
||||
- Engine user with Ops read grant opens an Ops-targeted run and can read the target card.
|
||||
- Engine user with Ops write grant creates or updates in the target Ops project.
|
||||
- Engine user without target Ops grant gets preflight denied and no token.
|
||||
- Ops-origin run can call Engine-side context once the Engine entitlement adapter exists.
|
||||
- Ops-origin run can call Engine-side context once `AI_WORKSPACE_ENGINE_ENTITLEMENT_URL` points at Engine `/api/ai-workspace/internal/v1/entitlements`.
|
||||
- Admin grants a user a new project permission; new AI Workspace run receives it without reinstalling the agent.
|
||||
- Admin revokes a project permission; new run token loses it and existing source-linked token grants stop resolving through deleted grants.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user