Access in Steerholm is the set of grants connecting an agent to the servers and
tools it may use. An agent starts with none — it can reach nothing until you grant
it. This guide covers wiring and auditing those connections, once an agent and a
server both exist (add an agent,
add a server).
Grant access
Grants are additive — each grant adds a rule to the agent’s policy. Grant a whole
server, a specific tool, or a tool constrained by its arguments:
See Permissions for the full glob/regex argument syntax.
Revoke access
--tool matches the exact pattern you granted, not a glob expansion of it.
If you granted --tool "git_diff*", revoke it with --tool "git_diff*", not
--tool "git_diff".
See what an agent can reach
show agent lists an agent’s access-key prefix and every grant it holds
(server → tools → argument constraints):
See who can reach a server
The reverse view — show server includes the agents that have been granted access,
alongside the server’s live status and tools: