{"role":"reader","running_as":"mitos-reader@upgradegr-mitos.iam.gserviceaccount.com","project":"upgradegr-mitos","may_call_write_tools":{"open_pull_request":false,"set_commit_status":false,"write_spec_repo":false},"spec_repo_write_credential":{"reachable":false,"detail":"PermissionDenied","message":"403 Permission 'secretmanager.versions.access' denied on resource (or it may not exist). Remediate access with this Troubleshooter URL or share it with your administrator - https://console.cloud.googl"},"model":"gemini-3.7-flash","models":{"primary_agent_model":"gemini-3.7-flash","primary_agent_provider":"Vertex AI","primary_agent_does":"the router, the specialists and the repository-reading agent","independent_critic_model":"google/gemma-4-26b-a4b-it-maas","independent_critic_provider":"Google Cloud managed open models","independent_critic_does":"reviews a sanitised draft and may add advisories for the human. It cannot approve, cannot clear a finding and cannot change a verdict, by construction rather than by instruction","independent_critic_last_review":null},"build_sha":"27c09d6","github_app_write":{"check_runs":true,"suggested_pull_requests":"behind a human approval","installation_token":"minted per request, never stored","credential_present":true,"reaches":"repositories the App was installed on, chosen by their owner"},"note":"may_call_write_tools covers the ADK tool path only. This service also makes direct GitHub App calls, check runs and a branch-file-pull-request sequence behind a human approval. Those do not pass through that callback and are reported under github_app_write. spec_repo_write_credential is enforced by Google IAM, outside this process, and is the load-bearing control: this service cannot grant itself the specification repository credential no matter what it decides."}