Right now the controller can see secrets across namespaces, so that level of isolation isn’t there yet. It’s on the roadmap though. Namespace-scoped secrets where a controller agent can spawn agents but can’t read their secrets is the right model.
No human approval flow yet either, agents create directly. Would you want something like klaw dispatch --approve that queues until a human confirms?
CGamesPlay|14 days ago
eftalyurtseven|14 days ago