OperationsSoftware EngineeringOpen accessPublished 3 Oct 2026
Operate Kuberly organization access safely through the Platform MCP permissions_management workflow: org users, roles, policies, groups, and activity logs. Covers the discover -> inspect -> propose-diff -> approve -> mutate -> verify loop, the user/role/group/policy RBAC model, scope/blast-radius, allow vs deny guardrails, least-surprising change selection, and the gated mutation tools (create/update/delete role/group, add/remove user/group roles, group membership, org-user status). Trigger on "give X access", "grant/revoke a role", "create a team group", "why does X have access", "make a viewer/admin role", "deactivate a user", "tighten overbroad access", or "who changed…