feat: remove agents-access role and enable Coder Agents by default - #28184
feat: remove agents-access role and enable Coder Agents by default#28184ibetitsmike wants to merge 11 commits into
Conversation
Chat permissions (create, read, share, update on owned chats) move from the removed org-scoped agents-access role into the organization-member permission floor, so every org member can use Coder Agents without a per-user grant. Service accounts remain excluded. Migration 000570 scrubs stored role strings so role expansion cannot fail after the built-in role is gone.
Docs previewCheck off each page once it's been reviewed. If a page changes in a later push, its checkbox clears automatically so it gets a fresh look. Pages not yet wired into the docs navigation aren't listed here. |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1c98b65c4f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Restore agents-access to non-service-account org memberships in the down migration so pre-removal binaries keep chat access on rollback, keep the deprecated codersdk.RoleAgentsAccess constant for source compatibility, and pin the chat access denied alert docs href in its story.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5ff3ead19a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5ff3ead19a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 314859e079
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Reserving the retired role name prevents a custom role from shadowing the built-in on rollback. The down migration no longer restores default_org_member_roles because pre-removal binaries union defaults into service-account memberships, which would grant every service account chat access.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f35dd8b1e4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 125d99d57d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 125d99d57d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…y in member stories
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8e5de52948
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6b4ab4108f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dd65b14a5e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Removes the org-scoped
agents-access("Coder Agents User") role and enables Coder Agents for every organization member by default.Closes https://linear.app/codercom/issue/CODAGT-554/remove-agents-access-role-and-enable-agents-by-default
Why
Coder Agents access previously required granting the
agents-accessrole user by user, per organization. There was no org-wide or default enablement, which made rollout painful. Per-user enablement is unusually unergonomic for basic product functionality, so Agents is now on by default for regular members.What changed
create,read,share,updateon owned chats; nodelete, hard-deletion stays in dbpurge) move into theorganization-memberpermission floor (OrgMemberPermissions). Theagents-accessbuilt-in role, its assignment entries, and its name helpers are deleted.ReservedRoleNamekeepsagents-accessreserved so a custom role cannot adopt the name and collide on rollback. Service accounts keep their own permission set (OrgServiceAccountPermissions) and do not receive chat access by default.agents-accessstrings fromorganization_members.roles,users.rbac_roles, andorganizations.default_org_member_roles; stale strings would otherwise fail role-update validation and render as raw labels in the UI. The down migration restores the role to all current non-service-account memberships so a rollback to an older binary preserves member chat access; org defaults are not restored because older binaries union them into service-account memberships too.codersdk.RoleAgentsAccessis retained as a deprecated constant for downstream Go consumers; types regenerated. Role description/sort metadata,MockAgentsAccessRole, and role-specific stories removed or repurposed. The frontend already gated on thecreateChatpermission (not the role name), so it now lights up for all members with no logic change. The chat access denied alert keeps working for the remaining denial case (service accounts) and no longer points at a deleted docs anchor.agents-accessfrom Terraform or scripted role sets, since role updates that still include it are rejected.TestListRoles, enterprise role listing, SSR permission, querier, migration, and Navbar/AgentCreateForm story tests updated.Notes for reviewers
ResourceChat; no handler checked the role name, so removing the role only changes which subjects hold the permissions.Remote dogfood UAT was run against this branch via a Coder Agent on dev.coder.com covering the plain-member happy path, role-list removal, migration scrubbing, and service-account denial.