Feature flags

Every switchable capability in Genesis is a feature in one code-defined catalog. This page is generated from that catalog; it is the complete list. There is no other registry of flags.

A feature has two levels, and the effective state is always the AND of both:

  1. Deploy level — whether the feature exists in this deployment. Set in the release values under services.core.features.<valuesKey>.enabled (the chart turns that into the Features__<key>__Enabled environment variable). Changing it is a GitOps change: a values merge, then the next rollout. A feature that is off at this level is shown locked in every tenant and cannot be turned on from inside the product.
  2. Tenant level — whether this tenant has it on. Tenant admins flip it at runtime from Settings → Features (/settings/features) or with the feature_set MCP tool; the change is audited as Feature:<key> and takes effect within a few seconds. When a tenant has never touched a feature, its tenant default applies. A deployment may override that default for all its tenants with services.core.features.<valuesKey>.tenantDefault.

Some rows carry no tenant switch:

  • Deploy-only — the feature is a platform-wide rail (a kill-switch, a runtime provider); the tenant screen shows its deploy state read-only.
  • Restart required — the value is consumed when the service starts, so a runtime flip could not take effect. The row is read-only and the only lever is the release values.

A few run-lane features can additionally be frozen at runtime: a platform-config row holding false under the feature's legacy path closes the gate without a rollout. The lever is one-way — it can only close a gate the deployment opened, never open one it closed — and un-freezing means clearing the row, not writing true.

How to read the tables

ColumnMeaning
KeyThe stable catalog key. It is the segment in Features__<key>__Enabled and the argument to feature_set.
Values keyThe camelCase key under services.core.features in the release values.
Tenant toggleYes — tenant admins may flip it; Deploy-only — read-only in the tenant screen; Restart required — read-only, needs a rollout.
Deploy defaultWhat the deploy level resolves to when the release values say nothing. Deployed environments always set it explicitly.
Tenant defaultWhat a tenant gets before anyone touches the switch.

Refusals you may meet: feature.deploy-disabled (the feature is off at the deploy level — nothing a tenant admin can do), feature.not-togglable (the row has no tenant switch), and the per-surface feature_disabled outcome a tool or endpoint returns when its feature is off for the tenant.

Integrations

KeyNameWhat it gatesValues keyTenant toggleDeploy defaultTenant defaultNotes
atlassianAtlassian integrationThe customer's Jira and Confluence: every atlassian_* read and write. Off means every verb refuses feature_disabled.atlassianYesoffonLegacy path Atlassian:Enabled still honoured; Fails closed on an unreadable tenant bit
atlassian-writesAtlassian writesThe approval-gated Atlassian write verbs (comments, worklogs, transitions, page edits). Reads keep working when this is off.atlassianWritesYesoffonLegacy path Atlassian:WriteEnabled still honoured; Fails closed on an unreadable tenant bit
product-atlassian-sitesProduct-scoped Atlassian sitesHonour a product's own Atlassian site binding (host, acting account, token) instead of the tenant's connection. A bound product with this off refuses Atlassian calls rather than falling back.productAtlassianSitesYesoffonLegacy path Atlassian:ProductSites:Enabled still honoured; Fails closed on an unreadable tenant bit
gitlab-customer-integrationCustomer GitLab integrationThe tenant's own GitLab: the customer lane that clones private upstreams and opens merge requests in the customer's group. Provisioning a tenant lane turns it on for that tenant.gitlabCustomerIntegrationYesoffonLegacy path GitLab:CustomerIntegration:Enabled still honoured; Fails closed on an unreadable tenant bit
gitlab-attributionGitLab call attributionRecord which identity made each GitLab call (the call-attempt ledger behind the identity and quota views).gitlabAttributionYesoffonLegacy path GitLab:Identity:Enabled still honoured; Fails closed on an unreadable tenant bit
mr-enrichmentMerge-request enrichmentEnrich a merge request with a generated description and review context when it is opened.mrEnrichmentYesononLegacy path MrEnrichment:Enabled still honoured; Fails closed on an unreadable tenant bit

Surfaces

KeyNameWhat it gatesValues keyTenant toggleDeploy defaultTenant defaultNotes
mcp-appsMCP Apps widgetsAnnotate MCP tool results and definitions with interactive widget resources (decision queue card) for hosts that support the MCP Apps extension. Off = fully dark: no metadata is emitted anywhere.mcpAppsYesoffonLegacy path McpApps:Enabled still honoured; Fails closed on an unreadable tenant bit
mcp-apps-genericMCP Apps generic cardRender read-only MCP tool results as a generic card (table, detail or status view) in hosts that support the MCP Apps extension, alongside the decision queue card. Requires mcp-apps; off = only the decision queue card is annotated.mcpAppsGenericYesoffoff—
run-artifactsRun artifactsPublishing and linking workflow-run artifacts (run_artifact_* tools, the artifacts API and share links).runArtifactsYesoffonLegacy path Artifacts:Enabled still honoured; Fails closed on an unreadable tenant bit
ops-read-planeOps read planeThe read-only operations surface (ops_* tools and the ops API) that answers cluster, pod and log questions about the tenant's own footprint.opsReadPlaneYesoffonLegacy path Ops:ReadPlane:Enabled still honoured; Fails closed on an unreadable tenant bit
operator-browse-live-viewOperator browse live viewShow the live noVNC view of a browsing session on the operator dashboard, and serve the proxy path behind it. Off, sessions still run and their artefacts are still collected; only the live window is absent. The row has no legacy path: the dashboard reads its own Features__OperatorBrowseLiveView env today, and moves to this row when it asks core for the effective value.operatorBrowseLiveViewDeploy-onlyoff——
operator-browse-input-lockOperator browse input lockLet an operator take exclusive input control of a live browsing session, locking the agent out while they drive. Requires the live view. No legacy path, for the same reason as the live-view row.operatorBrowseInputLockDeploy-onlyoff——
design-system-v2Design system v2Activate the v2 design-system stylesheet and the panels scoped to it across the dashboard. Off, the dashboard renders v1 exactly as before; the v2 stylesheet is inert rather than absent.designSystemV2Deploy-onlyoff—Legacy path Genesis:DesignSystem:V2Enabled still honoured

Missions and runs

KeyNameWhat it gatesValues keyTenant toggleDeploy defaultTenant defaultNotes
standing-agentsStanding agentsAutonomous standing agents (Strategic Orchestration, Compliance, per-Project, per-Product) run for this tenant: the dispatcher ticks them and the bootstraps create them. Turning it off stops new ticks and bootstraps; existing agents are left in place but idle.standingAgentsYesonoffLegacy path AgentDispatcher:Enabled still honoured
mission-runsMission runsThe mission-run lane: birthing a workflow run as an acceptance-gated unit, whether started on an existing mission (mission_run_start) or together with a new one (run-native workflow_invoke).missionRunsYesoffonLegacy path Workflows:MissionRuns:StartEnabled still honoured; Runtime freeze: a platform-config false under that path closes the gate; Fails closed on an unreadable tenant bit
run-executorRun executorAdvance workflow runs for this tenant: the mission sweep also picks up missions carrying an open run (whatever the mission's own status), dispatches their run-scoped tasks on the run lane, and integrates each on its run branch. Turning it off returns this tenant to the legacy status-driven sweep — open runs stop advancing; other tenants are unaffected.runExecutorYesononLegacy path Workflows:Runs:ExecutorEnabled still honoured; Runtime freeze: a platform-config false under that path closes the gate; Fails closed on an unreadable tenant bit
agent-driven-missionsAgent-driven missions by defaultMissions created without a stated lane — the dashboard Create Mission form with NO workflow attached, and API callers that omit useAgentDispatcher — run on the MissionAgent lane instead of the classic orchestrator sweep. Off (the default) = classic lane; each mission can still opt in explicitly. Does not affect workflow-attached or MCP-created missions, which are always classic/run-native.agentDrivenMissionsYesonoffLegacy path Missions:AgentDriven:Enabled still honoured
post-task-verificationPost-task verificationAfter a coding task lands, dispatch the system verification task (VERDICT VERIFIED or FAILED, no approval) before the mission moves on.postTaskVerificationYesononLegacy path Missions:Verification:Enabled still honoured; Fails closed on an unreadable tenant bit
run-native-invokeRun-native invocationMaterialise a workflow invocation as a run on the native execution lane instead of inline tasks. ANDed with mission-runs: both must be on.runNativeInvokeYesoffonLegacy path Workflows:Invoke:RunNative still honoured; Fails closed on an unreadable tenant bit
post-task-validationPost-task validationValidate a coding task's result after the coder finishes, before it counts as done.postTaskValidationYesononLegacy path PostTaskValidation:Enabled still honoured; Fails closed on an unreadable tenant bit
post-task-validation-testsPost-task test runRun the project's tests as part of post-task validation. Off, validation still runs but stops short of executing tests.postTaskValidationTestsYesononLegacy path PostTaskValidation:RunTests still honoured; Fails closed on an unreadable tenant bit
auto-regression-testsAutomatic regression testsGenerate a regression test for a fixed defect so the same failure cannot return unnoticed.autoRegressionTestsYesoffonLegacy path AutoRegressionTests:Enabled still honoured; Fails closed on an unreadable tenant bit
pre-review-acceptancePre-review acceptanceRun the acceptance pass before review rather than after, so a change that cannot be accepted never reaches a reviewer.preReviewAcceptanceYesoffonLegacy path Acceptance:PreReview:Enabled still honoured; Fails closed on an unreadable tenant bit
run-target-provisioningRun-target provisioningProvision a real environment to validate a run against. Costs money and cluster capacity per run, so each tenant can turn it off.runTargetProvisioningYesoffonLegacy path Acceptance:RunTargetProvisioning:LiveEnabled still honoured; Fails closed on an unreadable tenant bit
proposal-accept-starts-runAccepting a proposal starts a runStart a mission run as soon as a proposal is accepted, instead of leaving the mission for an operator to start. Off, acceptance records the decision and nothing else moves.proposalAcceptStartsRunYesoffonLegacy path Missions:ProposalAccept:StartRun still honoured; Fails closed on an unreadable tenant bit
agentic-decompositionAgentic mission decompositionDecompose a mission through the agentic sub-agent loop. Off, each mission is surrendered to operator-managed decomposition through an attention request — the kill-switch for when the agentic path regresses.agenticDecompositionYesononLegacy path Decomposition:UseAgenticMcp still honoured; Fails closed on an unreadable tenant bit
reaction-shadow-modeReaction engine shadow modeEvaluate attention requests but SUPPRESS every action the reaction engine would take, emitting the judgement stream instead. Platform-wide by design: it is how a policy change is watched before it is trusted, so it is deploy-only.reactionShadowModeDeploy-onlyoff—Legacy path Reaction:Engine:ShadowMode still honoured
aspect-repo-backed-analysisRepo-backed aspect analysisRoute aspect onboarding to the graph whose Vision analysis runs as a coder task against a real read-only checkout instead of in process. Requires the aspect-onboarding seam to be on and bound; when it cannot be honoured, onboarding fails loudly rather than falling back.aspectRepoBackedAnalysisYesoffonLegacy path Workflows:AspectOnboarding:RepoBackedAnalysis:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-first-run-onboardingSeam: First-run onboardingRoute the 'first-run-onboarding' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamFirstRunOnboardingYesoffonLegacy path Workflows:Seams:first-run-onboarding:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-aspect-onboardingSeam: Aspect onboardingRoute the 'aspect-onboarding' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamAspectOnboardingYesoffonLegacy path Workflows:Seams:aspect-onboarding:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-support-case-triageSeam: Support case triageRoute the 'support-case-triage' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamSupportCaseTriageYesoffonLegacy path Workflows:Seams:support-case-triage:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-review-engineSeam: Review engineRoute the 'review-engine' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamReviewEngineYesoffonLegacy path Workflows:Seams:review-engine:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-ux-reviewSeam: UX reviewRoute the 'ux-review' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamUxReviewYesoffonLegacy path Workflows:Seams:ux-review:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-improvement-cycleSeam: Improvement cycleRoute the 'improvement-cycle' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamImprovementCycleYesoffonLegacy path Workflows:Seams:improvement-cycle:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-decompose-directSeam: Direct decompositionRoute the 'decompose-direct' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamDecomposeDirectYesoffonLegacy path Workflows:Seams:decompose-direct:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-decompose-researchSeam: Research decompositionRoute the 'decompose-research' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamDecomposeResearchYesoffonLegacy path Workflows:Seams:decompose-research:Enabled still honoured; Fails closed on an unreadable tenant bit
workflow-seam-mission-decompose-groundedSeam: Grounded mission decompositionRoute the 'mission-decompose-grounded' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says.workflowSeamMissionDecomposeGroundedYesoffonLegacy path Workflows:Seams:mission-decompose-grounded:Enabled still honoured; Fails closed on an unreadable tenant bit
product-onboarding-autostartProduct onboarding autostartCreating a product starts its steward-driven onboarding interview (Onboarding mode); off = the operator starts it by hand from the product page.productOnboardingAutostartYesononFails closed on an unreadable tenant bit

Dialogue

KeyNameWhat it gatesValues keyTenant toggleDeploy defaultTenant defaultNotes
dialogue-escalationDialogue escalation to Claude CodeRoute a tool-using dialogue turn to the Claude Code harness backend instead of the in-process chat loop.dialogueEscalationYesoffoffLegacy path Dialogue:Escalation:Enabled still honoured
dialogue-write-toolsDialogue write toolsAllow in-process dialogue tools to run curated ACT/PROPOSE write operations. The deploy gate stays the hard rail; a tenant admin may arm the write tier at runtime.dialogueWriteToolsYesoffoffLegacy path Dialogue:InProcessTools:WriteEnabled still honoured
dialogue-bridge-mcpDialogue MCP bridgeExpose Genesis MCP tools to a dialogue turn through the tool bridge, so a model without native tool calling can still act.dialogueBridgeMcpYesononLegacy path Dialogue:BridgeMcp:Enabled still honoured; Fails closed on an unreadable tenant bit
dialogue-cross-mechanism-fallbackCross-mechanism fallbackLet a failing dialogue call fall back to a provider using a DIFFERENT mechanism, not just another model on the same one.dialogueCrossMechanismFallbackYesoffonLegacy path Dialogue:AllowCrossMechanismFallback still honoured; Fails closed on an unreadable tenant bit
native-tool-callingNative tool callingUse the provider's own tool-calling protocol where it has one, instead of the text-marker bridge.nativeToolCallingYesononLegacy path PromptCaching:NativeToolCallingEnabled still honoured; Fails closed on an unreadable tenant bit
dialogue-escalation-fallbackEscalation falls back in-processWhen an escalated dialogue turn's Claude Code dispatch fails, fall back once to the in-process path. Off, the turn fails with the dispatch instead of answering on the slower path.dialogueEscalationFallbackYesononLegacy path Dialogue:Escalation:FallbackToInProcess still honoured; Fails closed on an unreadable tenant bit
dialogue-escalation-on-tool-failureEscalate on tool failureOn a plain turn's recoverable provider failure (rate limit, exhaustion, credit block), escalate once to the Claude Code harness rather than returning the error.dialogueEscalationOnToolFailureYesoffonLegacy path Dialogue:Escalation:OnToolFailure still honoured; Fails closed on an unreadable tenant bit
dialogue-in-process-toolsIn-process dialogue toolsGive the dialogue providers core's own MCP tool registry (Tier-1 reads, in the caller's tenant scope) instead of the Bridge MCP sidecar, which no cloud deployment runs. Chosen once when the container is built, so changing it needs a rollout.dialogueInProcessToolsRestart requiredon—Restart required; Legacy path Dialogue:InProcessTools:Enabled still honoured

Intelligence

KeyNameWhat it gatesValues keyTenant toggleDeploy defaultTenant defaultNotes
auto-researchAutomatic deep researchAutomatically dispatch a deep-research mission when a dialogue turn asks for investigation and expert confidence is low.autoResearchYesononLegacy path Orchestrator:Research:AutoTriggerEnabled still honoured; Fails closed on an unreadable tenant bit
subscription-usage-harvestSubscription usage harvestHarvest provider subscription usage (quota windows, resets) from coder sessions into the usage ledger the cost and quota views read.subscriptionUsageHarvestYesoffonLegacy path SubscriptionUsage:HarvestEnabled still honoured; Fails closed on an unreadable tenant bit
web-research-harness-fallbackWeb research harness fallbackWhen the in-process web investigator cannot answer, fall back to a Claude Code harness session for the research step.webResearchHarnessFallbackYesoffonLegacy path Research:Web:HarnessFallbackEnabled still honoured; Fails closed on an unreadable tenant bit
search-synthesisSearch synthesisSynthesise a natural-language answer over the raw search hits (one model call per search) instead of returning the hits alone.searchSynthesisYesononLegacy path Search:SynthesisEnabled still honoured; Fails closed on an unreadable tenant bit
search-postgres-ftsPostgres full-text searchUse Postgres full-text search for conversation history search; off falls back to the simpler pattern match.searchPostgresFtsYesononLegacy path Search:PostgresFTS still honoured; Fails closed on an unreadable tenant bit
llm-snapshot-text-captureLLM snapshot text captureStore the prompt and completion text of every model call alongside its attempt record (the snapshot the call viewer shows). Off keeps only the metadata.llmSnapshotTextCaptureYesononLegacy path LlmSnapshots:CaptureText still honoured; Fails closed on an unreadable tenant bit
onboarding-auto-promoteOnboarding auto-promoteLet project onboarding promote stack readiness automatically when its checks pass, instead of waiting for an operator to confirm each stage.onboardingAutoPromoteYesoffonLegacy path Onboarding:AutoPromoteStackReadiness still honoured; Fails closed on an unreadable tenant bit
onboarding-knowledge-refreshOnboarding knowledge refreshThe background worker that regenerates aspect summaries and mirrors a project's own analyses into its knowledge corpus after onboarding writes its design tracker. Off, the terminal onboarding node still completes; the summaries and the mirror stay as they were until it is turned back on.onboardingKnowledgeRefreshYesononLegacy path Onboarding:KnowledgeRefreshEnabled still honoured; Fails closed on an unreadable tenant bit
ghost-evaluationGhost evaluationShadow-evaluate a sample of dialogues against alternative (ghost) models and record the comparison; never affects the answer the user sees.ghostEvaluationYesononLegacy path GhostEvaluation:Enabled still honoured; Fails closed on an unreadable tenant bit
ghost-judgeGhost judgeScore ghost-evaluation pairs with a judge model (a second call per sampled dialogue) instead of storing them unscored.ghostJudgeYesononLegacy path GhostEvaluation:JudgeEnabled still honoured; Fails closed on an unreadable tenant bit
learning-extractionLearning extractionExtract reusable lessons from completed work into the tenant's knowledge store.learningExtractionYesoffonLegacy path Learning:ExtractionEnabled still honoured; Fails closed on an unreadable tenant bit
maintenance-waveMaintenance waveRun the periodic maintenance wave that refreshes experts. Platform-wide loop: deploy-only.maintenanceWaveDeploy-onlyon—Legacy path Orchestrator:MaintenanceWaveEnabled still honoured
dialogue-intelligenceDialogue intelligenceMine dialogues for findings, themes and follow-ups instead of leaving them as transcript only.dialogueIntelligenceYesononLegacy path DialogueIntelligence:Enabled still honoured; Fails closed on an unreadable tenant bit
dialogue-intelligence-synthesisDialogue synthesisSynthesise the mined dialogue findings into a single briefing. Off, the findings are still recorded, just not summarised.dialogueIntelligenceSynthesisYesononLegacy path DialogueIntelligence:SynthesisEnabled still honoured; Fails closed on an unreadable tenant bit

Fleet and runtimes

KeyNameWhat it gatesValues keyTenant toggleDeploy defaultTenant defaultNotes
claude-code-harnessClaude Code agent runtimeMaster kill-switch for running an agent tick on the Claude Code harness runtime. A mode's claude-code RuntimeKind only activates when this deploy gate is on.claudeCodeHarnessDeploy-onlyoff—Legacy path AgentDispatcher:AllowClaudeCodeRuntime still honoured
claude-runtime-providerClaude runtime session podsRoute claude-tool coding/dialogue backends to the in-cluster claude-runtime session-pod provider.claudeRuntimeProviderDeploy-onlyoff—Legacy path Providers:Claude:RuntimeEnabled still honoured
browser-agent-surfaceBrowser agent surfaceThe EXTENDED browser-pool verbs: tabs, console/network readers, computer actions, upload, viewport resize, plus the server-side execution verbs (browser_eval, browser_snapshot, browser_run_spec). Off, the five original verbs — navigate, click, type, screenshot, task status — keep working; the extended twelve refuse.browserAgentSurfaceYesoffonLegacy path Browser:AgentSurface:Enabled still honoured; Fails closed on an unreadable tenant bit
windows-poolWindows poolThe Windows resource pool (.NET Framework 4.8 substrate): windows_* tools that lease a Windows worker for builds and tests that need it.windowsPoolYesoffonLegacy path Windows:Pool:Enabled still honoured; Fails closed on an unreadable tenant bit
pty-approval-capturePTY approval captureCapture a coder's interactive approval prompts from its terminal and route them to the decision queue instead of letting the session stall.ptyApprovalCaptureYesoffonLegacy path Pty:ApprovalGate:CaptureEnabled still honoured; Fails closed on an unreadable tenant bit
pty-auto-approvePTY auto-approveAnswer captured coder approval prompts automatically according to the tenant's approval policy, without a human decision.ptyAutoApproveYesoffonLegacy path Pty:ApprovalGate:AutoApprove still honoured; Fails closed on an unreadable tenant bit
plan-mode-launcherPlan-mode launcherStart read-only plan-mode coder sessions (plan_mode_session_start) that ground a proposal in the real repository before any write.planModeLauncherYesoffonLegacy path Pty:PlanMode:LauncherEnabled still honoured; Fails closed on an unreadable tenant bit
workspace-bridgeWorkspace bridgeLet a coding task reach its workspace through the workspace service rather than the pod filesystem alone.workspaceBridgeYesononLegacy path Workflows:WorkspaceBridge:Enabled still honoured; Fails closed on an unreadable tenant bit
coder-cost-reconciliationCoder cost reconciliationReconcile recorded coder costs against the provider's own accounting. Platform-wide reconciler: deploy-only.coderCostReconciliationDeploy-onlyon—Legacy path CoderCostReconciliation:Enabled still honoured
fleet-auth-preflightCoder auth preflightCheck that a usable LLM credential exists before starting a coder container, so an unauthenticated fleet fails at the gate instead of burning a container per task. Platform-wide: deploy-only.fleetAuthPreflightDeploy-onlyon—Legacy path Fleet:AuthPreflightEnabled still honoured
coder-tool-allowlistCoder tool allowlistNarrow a coder's tool surface to the allowlist its policy names. The policy is built once when the surface is composed, so changing it needs a rollout.coderToolAllowlistRestart requiredoff—Restart required; Legacy path Fleet:CoderToolAllowlist:Enabled still honoured
coder-cap-idle-evictionCap-blocked idle-container evictionWhen a coder cold start is blocked because the global or tenant container cap is full, evict the longest-idle coder container that is NOT busy to make room for the blocked start, instead of failing the request on saturation. Off by default: reclaiming a warm idle container is a capacity trade-off a deployment opts into.coderCapIdleEvictionYesoffoffLegacy path Fleet:CapBlockedIdleEviction:Enabled still honoured
copilot-per-tenantPer-tenant Copilot runtimeAddress each tenant's own Copilot runtime instead of a shared one. Deployment topology paired with the chart's copilot runtime pods: deploy-only, because a tenant routing itself at a shared runtime is an isolation change, not a preference.copilotPerTenantDeploy-onlyoff—Legacy path Providers:Copilot:PerTenant still honoured
junie-per-tenantPer-tenant Junie runtimeAddress each tenant's own Junie runtime instead of a shared one. Deployment topology paired with the chart's Junie runtime pods: deploy-only, for the same isolation reason as the Copilot row.juniePerTenantDeploy-onlyoff—Legacy path Providers:Junie:PerTenant still honoured

Governance

KeyNameWhat it gatesValues keyTenant toggleDeploy defaultTenant defaultNotes
compliance-overlayCompliance overlay floorInject the active control catalogue's floor (gates, checks, reviews) into workflows at publish, and enforce it. Postponed: off by default; the catalogue and the compliance program are unaffected.complianceOverlayYesoffoffLegacy path Workflows:ComplianceOverlay:Enabled still honoured
scoped-pre-approval-armScoped pre-approval armArm a scoped pre-approval on a workflow gate, so a decision already granted for that scope does not stop the run again.scopedPreApprovalArmYesoffonLegacy path Workflows:Gates:ScopedPreApprovalArm:Enabled still honoured; Fails closed on an unreadable tenant bit
sod-distinct-humanSeparation of duties: distinct humanRequire that the human who approves a governance decision is not the human who raised it. Off for a tenant, one person may raise and approve the same decision; the audit trail still records both acts against the same identity.sodDistinctHumanYesononLegacy path Governance:Sod:RequireDistinctHuman still honoured; Fails closed on an unreadable tenant bit
sod-role-awareSeparation of duties: role-awareExtend the distinct-human rule so that holding the raising ROLE disqualifies an approver even when the identity differs. Strictly narrows who may approve; it does nothing while the distinct-human rule itself is off.sodRoleAwareYesoffonLegacy path Governance:Sod:RoleAwareDistinctHuman still honoured; Fails closed on an unreadable tenant bit
dod-run-acceptanceDefinition of done: run acceptanceRequire an accepted mission run before a promotion seal is valid. Off, a seal may be granted on work that was never accepted on a run.dodRunAcceptanceYesoffonLegacy path Governance:Dod:RequireRunAcceptance still honoured; Fails closed on an unreadable tenant bit
retry-approvalRetry needs approvalRoute a failed task's retry through an operator decision instead of retrying it automatically. Off, retries proceed unattended and spend budget without a human in the loop.retryApprovalYesononLegacy path Missions:RequireRetryApproval still honoured; Fails closed on an unreadable tenant bit
brokered-credentials-requiredBrokered credentials requiredRefuse to spawn a coder unless its LLM credential is served through the credential broker. Off, a coder may start with a credential handed to it directly, which leaves no per-call broker record.brokeredCredentialsRequiredYesoffonLegacy path Fleet:RequireBrokeredCredentials still honoured; Fails closed on an unreadable tenant bit
task-env-allowlist-enforcedTask environment allowlist enforcedFilter the environment handed to a coder task down to the allowlisted variables. Off, the full computed environment is passed through, so a variable added anywhere upstream reaches the container.taskEnvAllowlistEnforcedYesoffonLegacy path Fleet:EnforceTaskEnvAllowlist still honoured; Fails closed on an unreadable tenant bit
redaction-feedRedaction capture feedRecord what the redaction layer removed from outbound LLM prompts. Redaction itself always runs; this only decides whether the evidence is written down. Deploy-only: the switch is read on EVERY outbound LLM call through a deliberately non-async fast path, so it is the deployment's bit rather than the tenant's.redactionFeedDeploy-onlyoff—Legacy path Redaction:FeedEnabled still honoured
compliance-floor-advisoryCompliance floor is advisoryReport a compliance-floor breach as a warning instead of blocking the publish. ON WEAKENS the floor: it is the escape hatch for a catalogue that is still being tuned, not a normal operating mode.complianceFloorAdvisoryYesoffonLegacy path Compliance:FloorAdvisory still honoured; Fails closed on an unreadable tenant bit
proposal-hygieneProposal hygiene checksScreen an agent's proposal for the malformed shapes that waste an operator's review. The check fails OPEN by design — if it cannot run, the proposal is allowed through rather than lost.proposalHygieneYesononLegacy path ProposalHygiene:Enabled still honoured; Fails closed on an unreadable tenant bit

Platform

KeyNameWhat it gatesValues keyTenant toggleDeploy defaultTenant defaultNotes
superrepo-fan-outSuperrepo fan-outOn adopting a monorepo, also mint one child project per successfully cloned submodule under the master project.superrepoFanOutYesoffonLegacy path Onboarding:SuperrepoFanOut still honoured; Fails closed on an unreadable tenant bit
product-tier-mintProduct tierMint the PRODUCT tier above projects during onboarding. Rides the superrepo fan-out: without it there is no product to mint.productTierMintYesoffonLegacy path Onboarding:ProductTier still honoured; Fails closed on an unreadable tenant bit
onboarding-resetOnboarding resetAllow an onboarding run to be RESET, discarding its progress. Destructive, so it stays deploy-only: no tenant switch can arm it.onboardingResetDeploy-onlyoff—Legacy path Onboarding:AllowReset still honoured
anthropic-usage-pollAnthropic usage pollingPoll Anthropic for subscription usage so quota state is known before a call is walled rather than after. Platform-wide poller: deploy-only.anthropicUsagePollDeploy-onlyoff—Legacy path Anthropic:UsagePollEnabled still honoured
platform-health-probesPlatform health probesRun the periodic platform health probes that feed governance status. Platform-wide loop: deploy-only.platformHealthProbesDeploy-onlyon—Legacy path PlatformHealthProbes:Enabled still honoured
synthetic-providerSynthetic quota pollingPoll the Synthetic provider for quota state. The service reads this once at construction, alongside its endpoint and interval, so the row is READ-ONLY: changing it needs a rollout.syntheticProviderRestart requiredoff—Restart required; Legacy path Synthetic:Enabled still honoured
git-mirror-per-tenantPer-tenant git mirrorRoute coder git traffic to the tenant's own git-mirror instance instead of the shared one. Deployment topology: deploy-only.gitMirrorPerTenantDeploy-onlyoff—Legacy path Services:GitMirror:PerTenant still honoured
environment-provisionerEnvironment provisionerProvision per-task environments on demand. Ships dark; enabling it lets task dispatch create cluster environments.environmentProvisionerDeploy-onlyoff—Legacy path Provisioner:Enabled still honoured
prompt-cachingPrompt cachingAsk the provider to cache the stable prefix of a prompt, so repeated context is billed and processed once.promptCachingYesononLegacy path PromptCaching:Enabled still honoured; Fails closed on an unreadable tenant bit
batch-processingBatch processingSend eligible work to the provider's batch API, trading latency for cost.batchProcessingYesononLegacy path BatchProcessing:Enabled still honoured; Fails closed on an unreadable tenant bit
ops-per-tenantPer-tenant ops planeRoute ops read-plane calls to each tenant's own ops service instead of a shared one. A boot rail: with per-tenant connection routing on, core REFUSES to start while this is off, so it is deploy-only and paired with the chart's ops topology.opsPerTenantDeploy-onlyoff—Legacy path Services:Ops:PerTenant still honoured
git-mirror-gitlab-proxyGit mirror proxies GitLabSend coder GitLab traffic through the git-mirror service rather than straight to GitLab. Wired when the execution host is composed, so changing it needs a rollout.gitMirrorGitlabProxyRestart requiredoff—Restart required; Legacy path GitMirror:ProxyGitLab still honoured
demo-modeDemo modePut the whole instance in demonstration mode: writes are refused and every LLM call is blocked at the provider. Chosen at startup — the provider registration itself changes — so it needs a rollout.demoModeRestart requiredoff—Restart required; Legacy path Genesis:DemoMode:Enabled still honoured

Generated from the feature catalog. Do not edit by hand — change the catalog and regenerate.