Root shell for assistant terminal sessions, with Owner-controlled access
Changes
A new MCP tool, elevate_terminal_session, switches a terminal session opened with
open_terminal_session to a root shell. A session opened through MCP starts as the depfloy user,
and every elevate_terminal_session call waits for your approval under Configuration → MCP →
Approvals, separately from the approval that opened the session. After that approval, everything
sent to the session runs as root. A session can be switched to root once, and the Activity log
records the root shell together with the approval that allowed it.
Assistant terminal access is now an organization setting. MCP terminal tools (open, type and elevate) work for the Owner’s assistants. To let Admin or Developer assistants use them, the Owner turns those roles on under Configuration → MCP → Connections → Terminal access for assistants; only the Owner can change this. Turning a role off refuses that role’s next terminal input or root request, including in sessions that are already open. The terminal in the browser keeps the same access for Owner, Admin and Developer.
See Terminal Sessions and MCP.