Feature flags
Every switchable capability in Genesis is a feature in one code-defined catalog. This page is generated from that catalog; it is the complete list. There is no other registry of flags.
A feature has two levels, and the effective state is always the AND of both:
- Deploy level — whether the feature exists in this deployment. Set in the release values
under
services.core.features.<valuesKey>.enabled(the chart turns that into theFeatures__<key>__Enabledenvironment variable). Changing it is a GitOps change: a values merge, then the next rollout. A feature that is off at this level is shown locked in every tenant and cannot be turned on from inside the product. - Tenant level — whether this tenant has it on. Tenant admins flip it at runtime from
Settings → Features (
/settings/features) or with thefeature_setMCP tool; the change is audited asFeature:<key>and takes effect within a few seconds. When a tenant has never touched a feature, its tenant default applies. A deployment may override that default for all its tenants withservices.core.features.<valuesKey>.tenantDefault.
Some rows carry no tenant switch:
- Deploy-only — the feature is a platform-wide rail (a kill-switch, a runtime provider); the tenant screen shows its deploy state read-only.
- Restart required — the value is consumed when the service starts, so a runtime flip could not take effect. The row is read-only and the only lever is the release values.
A few run-lane features can additionally be frozen at runtime: a platform-config row holding
false under the feature's legacy path closes the gate without a rollout. The lever is one-way —
it can only close a gate the deployment opened, never open one it closed — and un-freezing means
clearing the row, not writing true.
How to read the tables
| Column | Meaning |
|---|---|
| Key | The stable catalog key. It is the segment in Features__<key>__Enabled and the argument to feature_set. |
| Values key | The camelCase key under services.core.features in the release values. |
| Tenant toggle | Yes — tenant admins may flip it; Deploy-only — read-only in the tenant screen; Restart required — read-only, needs a rollout. |
| Deploy default | What the deploy level resolves to when the release values say nothing. Deployed environments always set it explicitly. |
| Tenant default | What a tenant gets before anyone touches the switch. |
Refusals you may meet: feature.deploy-disabled (the feature is off at the deploy level — nothing a
tenant admin can do), feature.not-togglable (the row has no tenant switch), and the per-surface
feature_disabled outcome a tool or endpoint returns when its feature is off for the tenant.
Integrations
| Key | Name | What it gates | Values key | Tenant toggle | Deploy default | Tenant default | Notes |
|---|---|---|---|---|---|---|---|
atlassian | Atlassian integration | The customer's Jira and Confluence: every atlassian_* read and write. Off means every verb refuses feature_disabled. | atlassian | Yes | off | on | Legacy path Atlassian:Enabled still honoured; Fails closed on an unreadable tenant bit |
atlassian-writes | Atlassian writes | The approval-gated Atlassian write verbs (comments, worklogs, transitions, page edits). Reads keep working when this is off. | atlassianWrites | Yes | off | on | Legacy path Atlassian:WriteEnabled still honoured; Fails closed on an unreadable tenant bit |
product-atlassian-sites | Product-scoped Atlassian sites | Honour a product's own Atlassian site binding (host, acting account, token) instead of the tenant's connection. A bound product with this off refuses Atlassian calls rather than falling back. | productAtlassianSites | Yes | off | on | Legacy path Atlassian:ProductSites:Enabled still honoured; Fails closed on an unreadable tenant bit |
gitlab-customer-integration | Customer GitLab integration | The tenant's own GitLab: the customer lane that clones private upstreams and opens merge requests in the customer's group. Provisioning a tenant lane turns it on for that tenant. | gitlabCustomerIntegration | Yes | off | on | Legacy path GitLab:CustomerIntegration:Enabled still honoured; Fails closed on an unreadable tenant bit |
gitlab-attribution | GitLab call attribution | Record which identity made each GitLab call (the call-attempt ledger behind the identity and quota views). | gitlabAttribution | Yes | off | on | Legacy path GitLab:Identity:Enabled still honoured; Fails closed on an unreadable tenant bit |
mr-enrichment | Merge-request enrichment | Enrich a merge request with a generated description and review context when it is opened. | mrEnrichment | Yes | on | on | Legacy path MrEnrichment:Enabled still honoured; Fails closed on an unreadable tenant bit |
Surfaces
| Key | Name | What it gates | Values key | Tenant toggle | Deploy default | Tenant default | Notes |
|---|---|---|---|---|---|---|---|
mcp-apps | MCP Apps widgets | Annotate MCP tool results and definitions with interactive widget resources (decision queue card) for hosts that support the MCP Apps extension. Off = fully dark: no metadata is emitted anywhere. | mcpApps | Yes | off | on | Legacy path McpApps:Enabled still honoured; Fails closed on an unreadable tenant bit |
mcp-apps-generic | MCP Apps generic card | Render read-only MCP tool results as a generic card (table, detail or status view) in hosts that support the MCP Apps extension, alongside the decision queue card. Requires mcp-apps; off = only the decision queue card is annotated. | mcpAppsGeneric | Yes | off | off | — |
run-artifacts | Run artifacts | Publishing and linking workflow-run artifacts (run_artifact_* tools, the artifacts API and share links). | runArtifacts | Yes | off | on | Legacy path Artifacts:Enabled still honoured; Fails closed on an unreadable tenant bit |
ops-read-plane | Ops read plane | The read-only operations surface (ops_* tools and the ops API) that answers cluster, pod and log questions about the tenant's own footprint. | opsReadPlane | Yes | off | on | Legacy path Ops:ReadPlane:Enabled still honoured; Fails closed on an unreadable tenant bit |
operator-browse-live-view | Operator browse live view | Show the live noVNC view of a browsing session on the operator dashboard, and serve the proxy path behind it. Off, sessions still run and their artefacts are still collected; only the live window is absent. The row has no legacy path: the dashboard reads its own Features__OperatorBrowseLiveView env today, and moves to this row when it asks core for the effective value. | operatorBrowseLiveView | Deploy-only | off | — | — |
operator-browse-input-lock | Operator browse input lock | Let an operator take exclusive input control of a live browsing session, locking the agent out while they drive. Requires the live view. No legacy path, for the same reason as the live-view row. | operatorBrowseInputLock | Deploy-only | off | — | — |
design-system-v2 | Design system v2 | Activate the v2 design-system stylesheet and the panels scoped to it across the dashboard. Off, the dashboard renders v1 exactly as before; the v2 stylesheet is inert rather than absent. | designSystemV2 | Deploy-only | off | — | Legacy path Genesis:DesignSystem:V2Enabled still honoured |
Missions and runs
| Key | Name | What it gates | Values key | Tenant toggle | Deploy default | Tenant default | Notes |
|---|---|---|---|---|---|---|---|
standing-agents | Standing agents | Autonomous standing agents (Strategic Orchestration, Compliance, per-Project, per-Product) run for this tenant: the dispatcher ticks them and the bootstraps create them. Turning it off stops new ticks and bootstraps; existing agents are left in place but idle. | standingAgents | Yes | on | off | Legacy path AgentDispatcher:Enabled still honoured |
mission-runs | Mission runs | The mission-run lane: birthing a workflow run as an acceptance-gated unit, whether started on an existing mission (mission_run_start) or together with a new one (run-native workflow_invoke). | missionRuns | Yes | off | on | Legacy path Workflows:MissionRuns:StartEnabled still honoured; Runtime freeze: a platform-config false under that path closes the gate; Fails closed on an unreadable tenant bit |
run-executor | Run executor | Advance workflow runs for this tenant: the mission sweep also picks up missions carrying an open run (whatever the mission's own status), dispatches their run-scoped tasks on the run lane, and integrates each on its run branch. Turning it off returns this tenant to the legacy status-driven sweep — open runs stop advancing; other tenants are unaffected. | runExecutor | Yes | on | on | Legacy path Workflows:Runs:ExecutorEnabled still honoured; Runtime freeze: a platform-config false under that path closes the gate; Fails closed on an unreadable tenant bit |
agent-driven-missions | Agent-driven missions by default | Missions created without a stated lane — the dashboard Create Mission form with NO workflow attached, and API callers that omit useAgentDispatcher — run on the MissionAgent lane instead of the classic orchestrator sweep. Off (the default) = classic lane; each mission can still opt in explicitly. Does not affect workflow-attached or MCP-created missions, which are always classic/run-native. | agentDrivenMissions | Yes | on | off | Legacy path Missions:AgentDriven:Enabled still honoured |
post-task-verification | Post-task verification | After a coding task lands, dispatch the system verification task (VERDICT VERIFIED or FAILED, no approval) before the mission moves on. | postTaskVerification | Yes | on | on | Legacy path Missions:Verification:Enabled still honoured; Fails closed on an unreadable tenant bit |
run-native-invoke | Run-native invocation | Materialise a workflow invocation as a run on the native execution lane instead of inline tasks. ANDed with mission-runs: both must be on. | runNativeInvoke | Yes | off | on | Legacy path Workflows:Invoke:RunNative still honoured; Fails closed on an unreadable tenant bit |
post-task-validation | Post-task validation | Validate a coding task's result after the coder finishes, before it counts as done. | postTaskValidation | Yes | on | on | Legacy path PostTaskValidation:Enabled still honoured; Fails closed on an unreadable tenant bit |
post-task-validation-tests | Post-task test run | Run the project's tests as part of post-task validation. Off, validation still runs but stops short of executing tests. | postTaskValidationTests | Yes | on | on | Legacy path PostTaskValidation:RunTests still honoured; Fails closed on an unreadable tenant bit |
auto-regression-tests | Automatic regression tests | Generate a regression test for a fixed defect so the same failure cannot return unnoticed. | autoRegressionTests | Yes | off | on | Legacy path AutoRegressionTests:Enabled still honoured; Fails closed on an unreadable tenant bit |
pre-review-acceptance | Pre-review acceptance | Run the acceptance pass before review rather than after, so a change that cannot be accepted never reaches a reviewer. | preReviewAcceptance | Yes | off | on | Legacy path Acceptance:PreReview:Enabled still honoured; Fails closed on an unreadable tenant bit |
run-target-provisioning | Run-target provisioning | Provision a real environment to validate a run against. Costs money and cluster capacity per run, so each tenant can turn it off. | runTargetProvisioning | Yes | off | on | Legacy path Acceptance:RunTargetProvisioning:LiveEnabled still honoured; Fails closed on an unreadable tenant bit |
proposal-accept-starts-run | Accepting a proposal starts a run | Start a mission run as soon as a proposal is accepted, instead of leaving the mission for an operator to start. Off, acceptance records the decision and nothing else moves. | proposalAcceptStartsRun | Yes | off | on | Legacy path Missions:ProposalAccept:StartRun still honoured; Fails closed on an unreadable tenant bit |
agentic-decomposition | Agentic mission decomposition | Decompose a mission through the agentic sub-agent loop. Off, each mission is surrendered to operator-managed decomposition through an attention request — the kill-switch for when the agentic path regresses. | agenticDecomposition | Yes | on | on | Legacy path Decomposition:UseAgenticMcp still honoured; Fails closed on an unreadable tenant bit |
reaction-shadow-mode | Reaction engine shadow mode | Evaluate attention requests but SUPPRESS every action the reaction engine would take, emitting the judgement stream instead. Platform-wide by design: it is how a policy change is watched before it is trusted, so it is deploy-only. | reactionShadowMode | Deploy-only | off | — | Legacy path Reaction:Engine:ShadowMode still honoured |
aspect-repo-backed-analysis | Repo-backed aspect analysis | Route aspect onboarding to the graph whose Vision analysis runs as a coder task against a real read-only checkout instead of in process. Requires the aspect-onboarding seam to be on and bound; when it cannot be honoured, onboarding fails loudly rather than falling back. | aspectRepoBackedAnalysis | Yes | off | on | Legacy path Workflows:AspectOnboarding:RepoBackedAnalysis:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-first-run-onboarding | Seam: First-run onboarding | Route the 'first-run-onboarding' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamFirstRunOnboarding | Yes | off | on | Legacy path Workflows:Seams:first-run-onboarding:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-aspect-onboarding | Seam: Aspect onboarding | Route the 'aspect-onboarding' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamAspectOnboarding | Yes | off | on | Legacy path Workflows:Seams:aspect-onboarding:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-support-case-triage | Seam: Support case triage | Route the 'support-case-triage' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamSupportCaseTriage | Yes | off | on | Legacy path Workflows:Seams:support-case-triage:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-review-engine | Seam: Review engine | Route the 'review-engine' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamReviewEngine | Yes | off | on | Legacy path Workflows:Seams:review-engine:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-ux-review | Seam: UX review | Route the 'ux-review' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamUxReview | Yes | off | on | Legacy path Workflows:Seams:ux-review:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-improvement-cycle | Seam: Improvement cycle | Route the 'improvement-cycle' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamImprovementCycle | Yes | off | on | Legacy path Workflows:Seams:improvement-cycle:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-decompose-direct | Seam: Direct decomposition | Route the 'decompose-direct' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamDecomposeDirect | Yes | off | on | Legacy path Workflows:Seams:decompose-direct:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-decompose-research | Seam: Research decomposition | Route the 'decompose-research' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamDecomposeResearch | Yes | off | on | Legacy path Workflows:Seams:decompose-research:Enabled still honoured; Fails closed on an unreadable tenant bit |
workflow-seam-mission-decompose-grounded | Seam: Grounded mission decomposition | Route the 'mission-decompose-grounded' built-in flow through its bound tenant workflow instead of the hard-coded path. Also requires an active seam binding with a published target; with no binding the built-in flow runs whatever this says. | workflowSeamMissionDecomposeGrounded | Yes | off | on | Legacy path Workflows:Seams:mission-decompose-grounded:Enabled still honoured; Fails closed on an unreadable tenant bit |
product-onboarding-autostart | Product onboarding autostart | Creating a product starts its steward-driven onboarding interview (Onboarding mode); off = the operator starts it by hand from the product page. | productOnboardingAutostart | Yes | on | on | Fails closed on an unreadable tenant bit |
Dialogue
| Key | Name | What it gates | Values key | Tenant toggle | Deploy default | Tenant default | Notes |
|---|---|---|---|---|---|---|---|
dialogue-escalation | Dialogue escalation to Claude Code | Route a tool-using dialogue turn to the Claude Code harness backend instead of the in-process chat loop. | dialogueEscalation | Yes | off | off | Legacy path Dialogue:Escalation:Enabled still honoured |
dialogue-write-tools | Dialogue write tools | Allow in-process dialogue tools to run curated ACT/PROPOSE write operations. The deploy gate stays the hard rail; a tenant admin may arm the write tier at runtime. | dialogueWriteTools | Yes | off | off | Legacy path Dialogue:InProcessTools:WriteEnabled still honoured |
dialogue-bridge-mcp | Dialogue MCP bridge | Expose Genesis MCP tools to a dialogue turn through the tool bridge, so a model without native tool calling can still act. | dialogueBridgeMcp | Yes | on | on | Legacy path Dialogue:BridgeMcp:Enabled still honoured; Fails closed on an unreadable tenant bit |
dialogue-cross-mechanism-fallback | Cross-mechanism fallback | Let a failing dialogue call fall back to a provider using a DIFFERENT mechanism, not just another model on the same one. | dialogueCrossMechanismFallback | Yes | off | on | Legacy path Dialogue:AllowCrossMechanismFallback still honoured; Fails closed on an unreadable tenant bit |
native-tool-calling | Native tool calling | Use the provider's own tool-calling protocol where it has one, instead of the text-marker bridge. | nativeToolCalling | Yes | on | on | Legacy path PromptCaching:NativeToolCallingEnabled still honoured; Fails closed on an unreadable tenant bit |
dialogue-escalation-fallback | Escalation falls back in-process | When an escalated dialogue turn's Claude Code dispatch fails, fall back once to the in-process path. Off, the turn fails with the dispatch instead of answering on the slower path. | dialogueEscalationFallback | Yes | on | on | Legacy path Dialogue:Escalation:FallbackToInProcess still honoured; Fails closed on an unreadable tenant bit |
dialogue-escalation-on-tool-failure | Escalate on tool failure | On a plain turn's recoverable provider failure (rate limit, exhaustion, credit block), escalate once to the Claude Code harness rather than returning the error. | dialogueEscalationOnToolFailure | Yes | off | on | Legacy path Dialogue:Escalation:OnToolFailure still honoured; Fails closed on an unreadable tenant bit |
dialogue-in-process-tools | In-process dialogue tools | Give the dialogue providers core's own MCP tool registry (Tier-1 reads, in the caller's tenant scope) instead of the Bridge MCP sidecar, which no cloud deployment runs. Chosen once when the container is built, so changing it needs a rollout. | dialogueInProcessTools | Restart required | on | — | Restart required; Legacy path Dialogue:InProcessTools:Enabled still honoured |
Intelligence
| Key | Name | What it gates | Values key | Tenant toggle | Deploy default | Tenant default | Notes |
|---|---|---|---|---|---|---|---|
auto-research | Automatic deep research | Automatically dispatch a deep-research mission when a dialogue turn asks for investigation and expert confidence is low. | autoResearch | Yes | on | on | Legacy path Orchestrator:Research:AutoTriggerEnabled still honoured; Fails closed on an unreadable tenant bit |
subscription-usage-harvest | Subscription usage harvest | Harvest provider subscription usage (quota windows, resets) from coder sessions into the usage ledger the cost and quota views read. | subscriptionUsageHarvest | Yes | off | on | Legacy path SubscriptionUsage:HarvestEnabled still honoured; Fails closed on an unreadable tenant bit |
web-research-harness-fallback | Web research harness fallback | When the in-process web investigator cannot answer, fall back to a Claude Code harness session for the research step. | webResearchHarnessFallback | Yes | off | on | Legacy path Research:Web:HarnessFallbackEnabled still honoured; Fails closed on an unreadable tenant bit |
search-synthesis | Search synthesis | Synthesise a natural-language answer over the raw search hits (one model call per search) instead of returning the hits alone. | searchSynthesis | Yes | on | on | Legacy path Search:SynthesisEnabled still honoured; Fails closed on an unreadable tenant bit |
search-postgres-fts | Postgres full-text search | Use Postgres full-text search for conversation history search; off falls back to the simpler pattern match. | searchPostgresFts | Yes | on | on | Legacy path Search:PostgresFTS still honoured; Fails closed on an unreadable tenant bit |
llm-snapshot-text-capture | LLM snapshot text capture | Store the prompt and completion text of every model call alongside its attempt record (the snapshot the call viewer shows). Off keeps only the metadata. | llmSnapshotTextCapture | Yes | on | on | Legacy path LlmSnapshots:CaptureText still honoured; Fails closed on an unreadable tenant bit |
onboarding-auto-promote | Onboarding auto-promote | Let project onboarding promote stack readiness automatically when its checks pass, instead of waiting for an operator to confirm each stage. | onboardingAutoPromote | Yes | off | on | Legacy path Onboarding:AutoPromoteStackReadiness still honoured; Fails closed on an unreadable tenant bit |
onboarding-knowledge-refresh | Onboarding knowledge refresh | The background worker that regenerates aspect summaries and mirrors a project's own analyses into its knowledge corpus after onboarding writes its design tracker. Off, the terminal onboarding node still completes; the summaries and the mirror stay as they were until it is turned back on. | onboardingKnowledgeRefresh | Yes | on | on | Legacy path Onboarding:KnowledgeRefreshEnabled still honoured; Fails closed on an unreadable tenant bit |
ghost-evaluation | Ghost evaluation | Shadow-evaluate a sample of dialogues against alternative (ghost) models and record the comparison; never affects the answer the user sees. | ghostEvaluation | Yes | on | on | Legacy path GhostEvaluation:Enabled still honoured; Fails closed on an unreadable tenant bit |
ghost-judge | Ghost judge | Score ghost-evaluation pairs with a judge model (a second call per sampled dialogue) instead of storing them unscored. | ghostJudge | Yes | on | on | Legacy path GhostEvaluation:JudgeEnabled still honoured; Fails closed on an unreadable tenant bit |
learning-extraction | Learning extraction | Extract reusable lessons from completed work into the tenant's knowledge store. | learningExtraction | Yes | off | on | Legacy path Learning:ExtractionEnabled still honoured; Fails closed on an unreadable tenant bit |
maintenance-wave | Maintenance wave | Run the periodic maintenance wave that refreshes experts. Platform-wide loop: deploy-only. | maintenanceWave | Deploy-only | on | — | Legacy path Orchestrator:MaintenanceWaveEnabled still honoured |
dialogue-intelligence | Dialogue intelligence | Mine dialogues for findings, themes and follow-ups instead of leaving them as transcript only. | dialogueIntelligence | Yes | on | on | Legacy path DialogueIntelligence:Enabled still honoured; Fails closed on an unreadable tenant bit |
dialogue-intelligence-synthesis | Dialogue synthesis | Synthesise the mined dialogue findings into a single briefing. Off, the findings are still recorded, just not summarised. | dialogueIntelligenceSynthesis | Yes | on | on | Legacy path DialogueIntelligence:SynthesisEnabled still honoured; Fails closed on an unreadable tenant bit |
Fleet and runtimes
| Key | Name | What it gates | Values key | Tenant toggle | Deploy default | Tenant default | Notes |
|---|---|---|---|---|---|---|---|
claude-code-harness | Claude Code agent runtime | Master kill-switch for running an agent tick on the Claude Code harness runtime. A mode's claude-code RuntimeKind only activates when this deploy gate is on. | claudeCodeHarness | Deploy-only | off | — | Legacy path AgentDispatcher:AllowClaudeCodeRuntime still honoured |
claude-runtime-provider | Claude runtime session pods | Route claude-tool coding/dialogue backends to the in-cluster claude-runtime session-pod provider. | claudeRuntimeProvider | Deploy-only | off | — | Legacy path Providers:Claude:RuntimeEnabled still honoured |
browser-agent-surface | Browser agent surface | The EXTENDED browser-pool verbs: tabs, console/network readers, computer actions, upload, viewport resize, plus the server-side execution verbs (browser_eval, browser_snapshot, browser_run_spec). Off, the five original verbs — navigate, click, type, screenshot, task status — keep working; the extended twelve refuse. | browserAgentSurface | Yes | off | on | Legacy path Browser:AgentSurface:Enabled still honoured; Fails closed on an unreadable tenant bit |
windows-pool | Windows pool | The Windows resource pool (.NET Framework 4.8 substrate): windows_* tools that lease a Windows worker for builds and tests that need it. | windowsPool | Yes | off | on | Legacy path Windows:Pool:Enabled still honoured; Fails closed on an unreadable tenant bit |
pty-approval-capture | PTY approval capture | Capture a coder's interactive approval prompts from its terminal and route them to the decision queue instead of letting the session stall. | ptyApprovalCapture | Yes | off | on | Legacy path Pty:ApprovalGate:CaptureEnabled still honoured; Fails closed on an unreadable tenant bit |
pty-auto-approve | PTY auto-approve | Answer captured coder approval prompts automatically according to the tenant's approval policy, without a human decision. | ptyAutoApprove | Yes | off | on | Legacy path Pty:ApprovalGate:AutoApprove still honoured; Fails closed on an unreadable tenant bit |
plan-mode-launcher | Plan-mode launcher | Start read-only plan-mode coder sessions (plan_mode_session_start) that ground a proposal in the real repository before any write. | planModeLauncher | Yes | off | on | Legacy path Pty:PlanMode:LauncherEnabled still honoured; Fails closed on an unreadable tenant bit |
workspace-bridge | Workspace bridge | Let a coding task reach its workspace through the workspace service rather than the pod filesystem alone. | workspaceBridge | Yes | on | on | Legacy path Workflows:WorkspaceBridge:Enabled still honoured; Fails closed on an unreadable tenant bit |
coder-cost-reconciliation | Coder cost reconciliation | Reconcile recorded coder costs against the provider's own accounting. Platform-wide reconciler: deploy-only. | coderCostReconciliation | Deploy-only | on | — | Legacy path CoderCostReconciliation:Enabled still honoured |
fleet-auth-preflight | Coder auth preflight | Check that a usable LLM credential exists before starting a coder container, so an unauthenticated fleet fails at the gate instead of burning a container per task. Platform-wide: deploy-only. | fleetAuthPreflight | Deploy-only | on | — | Legacy path Fleet:AuthPreflightEnabled still honoured |
coder-tool-allowlist | Coder tool allowlist | Narrow a coder's tool surface to the allowlist its policy names. The policy is built once when the surface is composed, so changing it needs a rollout. | coderToolAllowlist | Restart required | off | — | Restart required; Legacy path Fleet:CoderToolAllowlist:Enabled still honoured |
coder-cap-idle-eviction | Cap-blocked idle-container eviction | When a coder cold start is blocked because the global or tenant container cap is full, evict the longest-idle coder container that is NOT busy to make room for the blocked start, instead of failing the request on saturation. Off by default: reclaiming a warm idle container is a capacity trade-off a deployment opts into. | coderCapIdleEviction | Yes | off | off | Legacy path Fleet:CapBlockedIdleEviction:Enabled still honoured |
copilot-per-tenant | Per-tenant Copilot runtime | Address each tenant's own Copilot runtime instead of a shared one. Deployment topology paired with the chart's copilot runtime pods: deploy-only, because a tenant routing itself at a shared runtime is an isolation change, not a preference. | copilotPerTenant | Deploy-only | off | — | Legacy path Providers:Copilot:PerTenant still honoured |
junie-per-tenant | Per-tenant Junie runtime | Address each tenant's own Junie runtime instead of a shared one. Deployment topology paired with the chart's Junie runtime pods: deploy-only, for the same isolation reason as the Copilot row. | juniePerTenant | Deploy-only | off | — | Legacy path Providers:Junie:PerTenant still honoured |
Governance
| Key | Name | What it gates | Values key | Tenant toggle | Deploy default | Tenant default | Notes |
|---|---|---|---|---|---|---|---|
compliance-overlay | Compliance overlay floor | Inject the active control catalogue's floor (gates, checks, reviews) into workflows at publish, and enforce it. Postponed: off by default; the catalogue and the compliance program are unaffected. | complianceOverlay | Yes | off | off | Legacy path Workflows:ComplianceOverlay:Enabled still honoured |
scoped-pre-approval-arm | Scoped pre-approval arm | Arm a scoped pre-approval on a workflow gate, so a decision already granted for that scope does not stop the run again. | scopedPreApprovalArm | Yes | off | on | Legacy path Workflows:Gates:ScopedPreApprovalArm:Enabled still honoured; Fails closed on an unreadable tenant bit |
sod-distinct-human | Separation of duties: distinct human | Require that the human who approves a governance decision is not the human who raised it. Off for a tenant, one person may raise and approve the same decision; the audit trail still records both acts against the same identity. | sodDistinctHuman | Yes | on | on | Legacy path Governance:Sod:RequireDistinctHuman still honoured; Fails closed on an unreadable tenant bit |
sod-role-aware | Separation of duties: role-aware | Extend the distinct-human rule so that holding the raising ROLE disqualifies an approver even when the identity differs. Strictly narrows who may approve; it does nothing while the distinct-human rule itself is off. | sodRoleAware | Yes | off | on | Legacy path Governance:Sod:RoleAwareDistinctHuman still honoured; Fails closed on an unreadable tenant bit |
dod-run-acceptance | Definition of done: run acceptance | Require an accepted mission run before a promotion seal is valid. Off, a seal may be granted on work that was never accepted on a run. | dodRunAcceptance | Yes | off | on | Legacy path Governance:Dod:RequireRunAcceptance still honoured; Fails closed on an unreadable tenant bit |
retry-approval | Retry needs approval | Route a failed task's retry through an operator decision instead of retrying it automatically. Off, retries proceed unattended and spend budget without a human in the loop. | retryApproval | Yes | on | on | Legacy path Missions:RequireRetryApproval still honoured; Fails closed on an unreadable tenant bit |
brokered-credentials-required | Brokered credentials required | Refuse to spawn a coder unless its LLM credential is served through the credential broker. Off, a coder may start with a credential handed to it directly, which leaves no per-call broker record. | brokeredCredentialsRequired | Yes | off | on | Legacy path Fleet:RequireBrokeredCredentials still honoured; Fails closed on an unreadable tenant bit |
task-env-allowlist-enforced | Task environment allowlist enforced | Filter the environment handed to a coder task down to the allowlisted variables. Off, the full computed environment is passed through, so a variable added anywhere upstream reaches the container. | taskEnvAllowlistEnforced | Yes | off | on | Legacy path Fleet:EnforceTaskEnvAllowlist still honoured; Fails closed on an unreadable tenant bit |
redaction-feed | Redaction capture feed | Record what the redaction layer removed from outbound LLM prompts. Redaction itself always runs; this only decides whether the evidence is written down. Deploy-only: the switch is read on EVERY outbound LLM call through a deliberately non-async fast path, so it is the deployment's bit rather than the tenant's. | redactionFeed | Deploy-only | off | — | Legacy path Redaction:FeedEnabled still honoured |
compliance-floor-advisory | Compliance floor is advisory | Report a compliance-floor breach as a warning instead of blocking the publish. ON WEAKENS the floor: it is the escape hatch for a catalogue that is still being tuned, not a normal operating mode. | complianceFloorAdvisory | Yes | off | on | Legacy path Compliance:FloorAdvisory still honoured; Fails closed on an unreadable tenant bit |
proposal-hygiene | Proposal hygiene checks | Screen an agent's proposal for the malformed shapes that waste an operator's review. The check fails OPEN by design — if it cannot run, the proposal is allowed through rather than lost. | proposalHygiene | Yes | on | on | Legacy path ProposalHygiene:Enabled still honoured; Fails closed on an unreadable tenant bit |
Platform
| Key | Name | What it gates | Values key | Tenant toggle | Deploy default | Tenant default | Notes |
|---|---|---|---|---|---|---|---|
superrepo-fan-out | Superrepo fan-out | On adopting a monorepo, also mint one child project per successfully cloned submodule under the master project. | superrepoFanOut | Yes | off | on | Legacy path Onboarding:SuperrepoFanOut still honoured; Fails closed on an unreadable tenant bit |
product-tier-mint | Product tier | Mint the PRODUCT tier above projects during onboarding. Rides the superrepo fan-out: without it there is no product to mint. | productTierMint | Yes | off | on | Legacy path Onboarding:ProductTier still honoured; Fails closed on an unreadable tenant bit |
onboarding-reset | Onboarding reset | Allow an onboarding run to be RESET, discarding its progress. Destructive, so it stays deploy-only: no tenant switch can arm it. | onboardingReset | Deploy-only | off | — | Legacy path Onboarding:AllowReset still honoured |
anthropic-usage-poll | Anthropic usage polling | Poll Anthropic for subscription usage so quota state is known before a call is walled rather than after. Platform-wide poller: deploy-only. | anthropicUsagePoll | Deploy-only | off | — | Legacy path Anthropic:UsagePollEnabled still honoured |
platform-health-probes | Platform health probes | Run the periodic platform health probes that feed governance status. Platform-wide loop: deploy-only. | platformHealthProbes | Deploy-only | on | — | Legacy path PlatformHealthProbes:Enabled still honoured |
synthetic-provider | Synthetic quota polling | Poll the Synthetic provider for quota state. The service reads this once at construction, alongside its endpoint and interval, so the row is READ-ONLY: changing it needs a rollout. | syntheticProvider | Restart required | off | — | Restart required; Legacy path Synthetic:Enabled still honoured |
git-mirror-per-tenant | Per-tenant git mirror | Route coder git traffic to the tenant's own git-mirror instance instead of the shared one. Deployment topology: deploy-only. | gitMirrorPerTenant | Deploy-only | off | — | Legacy path Services:GitMirror:PerTenant still honoured |
environment-provisioner | Environment provisioner | Provision per-task environments on demand. Ships dark; enabling it lets task dispatch create cluster environments. | environmentProvisioner | Deploy-only | off | — | Legacy path Provisioner:Enabled still honoured |
prompt-caching | Prompt caching | Ask the provider to cache the stable prefix of a prompt, so repeated context is billed and processed once. | promptCaching | Yes | on | on | Legacy path PromptCaching:Enabled still honoured; Fails closed on an unreadable tenant bit |
batch-processing | Batch processing | Send eligible work to the provider's batch API, trading latency for cost. | batchProcessing | Yes | on | on | Legacy path BatchProcessing:Enabled still honoured; Fails closed on an unreadable tenant bit |
ops-per-tenant | Per-tenant ops plane | Route ops read-plane calls to each tenant's own ops service instead of a shared one. A boot rail: with per-tenant connection routing on, core REFUSES to start while this is off, so it is deploy-only and paired with the chart's ops topology. | opsPerTenant | Deploy-only | off | — | Legacy path Services:Ops:PerTenant still honoured |
git-mirror-gitlab-proxy | Git mirror proxies GitLab | Send coder GitLab traffic through the git-mirror service rather than straight to GitLab. Wired when the execution host is composed, so changing it needs a rollout. | gitMirrorGitlabProxy | Restart required | off | — | Restart required; Legacy path GitMirror:ProxyGitLab still honoured |
demo-mode | Demo mode | Put the whole instance in demonstration mode: writes are refused and every LLM call is blocked at the provider. Chosen at startup — the provider registration itself changes — so it needs a rollout. | demoMode | Restart required | off | — | Restart required; Legacy path Genesis:DemoMode:Enabled still honoured |
Generated from the feature catalog. Do not edit by hand — change the catalog and regenerate.