Skip to content

[OpenSpec] hermiq-ai-tooling #177

Description

@github-actions

⚠️ OpenSpec-managed issue — this content is automatically synced
from the openspec/ directory. Manual edits will be overwritten on next sync.

Artifacts

Summary

Extends portaliq-mcp-adoption — it does not replace or repeat it. That change (see
openspec/changes/portaliq-mcp-adoption/) deletes the app-template scaffold and gives portaliq a
two-tool read surface on the portal inbox
(specs/portaliq-mcp-surface/spec.md#requirement-a-curated-read-only-dialect-on-the-portal-inbox).
This change takes the next step the product framing asks for: every internal staff action
portaliq offers becomes an MCP tool
, so any of them can in principle be automated by an AI agent
— and every one of them is governed by hermiq's per-agent grant model (scope
read/create/update/delete × reach self/user/instance/external, default-deny
writes, human approval gates, audit trail). Even without automation, this is what makes chat a way
of commanding the app: an operator chats while portaliq executes.

Two hard lines are stated normatively, not as intentions: writes are curated tools only (the
schema-derived catalog stays read-only, preserving portaliq-mcp-adoption's
#requirement-a-curated-read-only-dialect-on-the-portal-inbox reasoning), and MCP tools serve
internal staff and their agents only — the surface is never reachable from, or exposed at, the
external portal edge (ADR-046).

Specs

Tasks

  • Implement
  • Test
  • Implement
  • Test
  • Implement
  • Test
  • Implement
  • Test
  • Implement
  • Test
  • Implement
  • Test

Design

See design.md for technical design details.


Synced from openspec/changes/hermiq-ai-tooling by OpenSpec workflow
App: portaliq

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions