Fix production without access to production.
Caster turns the dangerous parts of running production into spells: named actions your team casts, each under a permission scoped to that action alone.
Checkout is down.
Take the ticket and bring it back without ever holding a credential.
Nobody holds a credential to production.
A spell carries only the verbs its action needs, and your own API server enforces that limit rather than trusting our code.
caster · demo · simulation
/revivify payments-db
✗ revivify is not granted to you for payments-db
payments-db runs in the platform namespace. Your revivify grant is scoped to storefront.
refused · out of your namespaces · logged
Read the full permission model, worst case first.
Every spell in the book
Each one is a single action, packaged so the right way to do it is the only way it works.
An agent is just another employee.
Give an agent /scry and it can read the logs of the services you named, and it can do nothing else at all.
caster · demo · simulation
oncall-agent: requesting the restart: /revivify cart-api
✗ oncall-agent doesn't hold /revivify
Its grant is /scry on storefront services. A restart needs a human holding the spell.
refused · cast by oncall-agent · logged
The failure this prevents has a name: excessive agency.
Run it in your own cluster.
Casteris pre-launch; leave an address and you'll hear first.
For the security review, read what stays in your cluster and what leaves.