Skip to main content
Access in Steerholm is the set of grants connecting an agent to the servers and tools it may use. An agent starts with none — it can reach nothing until you grant it. This guide covers wiring and auditing those connections, once an agent and a server both exist (add an agent, add a server).

Grant access

Grants are additive — each grant adds a rule to the agent’s policy. Grant a whole server, a specific tool, or a tool constrained by its arguments:
See Permissions for the full glob/regex argument syntax.

Revoke access

--tool matches the exact pattern you granted, not a glob expansion of it. If you granted --tool "git_diff*", revoke it with --tool "git_diff*", not --tool "git_diff".

See what an agent can reach

show agent lists an agent’s access-key prefix and every grant it holds (server → tools → argument constraints):

See who can reach a server

The reverse view — show server includes the agents that have been granted access, alongside the server’s live status and tools: