Diff
1diff --git a/dot_config/opencode/AGENTS.md b/dot_config/opencode/AGENTS.md
2index a431e9897843000faef38c6cda14b2e9b6fafb7f..eb106cb69de586ba012cf21ebb304c13a9b011a9 100644
3--- a/dot_config/opencode/AGENTS.md
4+++ b/dot_config/opencode/AGENTS.md
5@@ -46,6 +46,6 @@ Specific footguns:
6
7 ## Remote access
8
9-Never access remote systems, like databases, Kubernetes, AWS, etc.
10-Services that are necessary for development are fine, e.g. GitHub for PRs
11+Never mutate remote systems, like databases, Kubernetes, AWS, etc.
12+Services that are used for development (GitHub, Grafana, etc.) are fine to write to when prompted.
13 Full local docker access is also allowed
14diff --git a/dot_pi/agent/policy-engine.json b/dot_pi/agent/policy-engine.json
15index 194b402f907a20c562e88c02ce92ec9c1757857b..71f221e4625f1afde116cb9b1aea0fac8ff51d06 100644
16--- a/dot_pi/agent/policy-engine.json
17+++ b/dot_pi/agent/policy-engine.json
18@@ -7,6 +7,10 @@
19 "permission": {
20 "read": "allow",
21 "write": "allow",
22+ "edit": "allow",
23+ "find": "allow",
24+ "grep": "allow",
25+ "ls": "allow",
26 "bash": {
27 "*sudo*": "deny",
28 "terraform apply*": "deny"