What you can do
Review every change before it happens
Deploys that change what is running, and cluster create, grow and delete, open an approval in the local dashboard at127.0.0.1:7419. It shows what will change, warnings and the cost impact. Nothing happens until you approve.
How: Ask Monk, then approve in the local dashboard. See Local dashboard.
Confirm destructive actions by name
Approvals for destructive actions, such as deleting a cluster, ask you to type the name of the thing being deleted. How: you approve it in the local dashboard. See Security.Keep the agent from approving itself
Approvals are created by Monk’s tools and answered by a click in your dashboard session. The coding agent can’t approve its own request. How: built in. See Security.Keep secrets out of the chat
Credentials and secrets are entered in forms in the local dashboard. Monk’s tools return names and metadata, never values, so the model sees which secrets exist but not what they contain. How: Ask Monk, then fill in the form in the local dashboard. See Secrets and configuration.Store them safely, push them when needed
Local secrets are kept in your operating system’s credential store (macOS Keychain, Linux Secret Service, Windows DPAPI), or an encrypted file where there is none. Monk pushes a named secret to the cluster when a deploy needs it, or when you ask. How: Ask Monk. See Secrets and configuration.Control writes to cluster secrets
Adding, pushing or removing a secret at a cluster scope (organization, project, environment or account) needs your approval, and the approval shows where the secret will land. How: Ask Monk, then approve in the local dashboard. See Security.Enforce permissions in the tools
In an organization, Monk’s tools check your role before acting and refuse what it doesn’t allow. How: built in. See Teams and access.Try it
Good to know
- Your coding agent is a separate program with its own permissions. Monk can’t limit what it does outside Monk’s tools, so review its own approval settings too.
- Monk doesn’t edit your application code. Your coding agent writes the configuration, and Monk validates and deploys it.
- If you paste a secret into chat by accident, rotate it.
Related
Secrets and configuration
Add and remove secrets
Local dashboard
Where approvals and forms appear
Security
What needs approval and how secrets are stored

