Repository navigation
EE permissions extension: is it available to self-hosted operators, and what does "open by default" cover without it? #10333
Replies: 1 comment
|
Nothing in the public repo, docs, or npm registry currently references a published "EE permissions extension" — it looks like the Trust panel string is pointing at planned/internal functionality rather than something shipped today. I couldn't find it as an installable package or in plugin examples either, so your read that it's not currently obtainable by self-hosters seems right as of now. Worth confirming with a maintainer directly (issue or Discord) rather than assuming, since roadmap items sometimes get referenced in UI copy before release. On your second question: your reading matches what's observable. "Open by default" describes company/member visibility, not tool access — the Tools tab behavior you describe (0 allowed tools, prompt can narrow but not expand) is consistent with tool permissions being deny-by-default independent of the EE extension. A docs PR clarifying that distinction would genuinely help — the current phrasing does read as more alarming than the actual behavior. |
Uh oh!
There was an error while loading. Please reload this page.
Running a self-hosted
local_trustedinstance (v2026.722.0, embedded Postgres) to operate a small governed agent org. Two questions about the EE permissions extension that I couldn't answer from the docs or the repo.Context for why I'm asking: the agent Configuration -> Trust panel says "Advanced permissions remain editable through the EE permissions extension when installed." That's the only mention I can find of it.
plugin exampleslists nothing, and I couldn't find it published as an npm package.1. Is the EE permissions extension available to self-hosted operators, and if so on what terms?
I'm not asking you to make it free — I'd just like to know whether it's obtainable at all so I can plan around it. Related: the paperclip.inc hosted plan describes itself as "everything you would get self-hosting, without running it yourself," which I read as meaning the hosted plan would not include it either. Is that right?
2. What does "companies remain open by default" actually cover without EE?
I've seen this phrasing used about running without the EE permissions extension, and I want to make sure I'm not misreading it as weaker than it is — or stronger.
My current understanding from inspecting a live instance is that it refers to company-level member/agent visibility, not tool access, because tool access is clearly default-deny: the agent Tools tab reports "no permitted apps," "0 allowed tools," "no active profile," and states that an agent's prompt "can narrow this list but cannot expand it." That reads as a hard ceiling to me.
If that's correct, it would be worth saying so somewhere in the docs — "open by default" sounds alarming to anyone evaluating Paperclip for governance use, when the tool layer is actually deny-by-default. If it's not correct, I'd rather find out now.
Happy to contribute a docs PR once I know the right answer.
Thanks — the governance model is the reason we picked Paperclip, so I'd like to understand its edges properly.
All reactions