cd /news/ai-agents/noroles-run-a-company-of-people-and-… · home › topics › ai-agents › article
[ARTICLE · art-141178] src=github.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

NoRoles – run a company of people and AI agents on permissions

NoRoles launched an MIT-licensed open-source tool that replaces corporate roles and titles with a permission list, letting AI agents act with exactly their person's permissions and requiring a human sign-off only for irreversible actions such as money leaving, contracts, public words, and personal data. The `noroles` command line, installed via `npx noroles init my-company`, supports commands including `noroles open`, `noroles ask`, `noroles yes`, `noroles do`, `noroles run`, and `noroles mcp-config`, and routes every MCP tool call through NoRoles. The project ships a MANIFESTO.md with eighteen principles and a SPEC.md defining permissions, mandates, rules, eight laws, and orchestrator enforcement, and requires every change to approval behavior to add a test in `npm/test/laws.test.js` naming the law or attack it covers.

read1 min views2 publishedSep 28, 2026
NoRoles – run a company of people and AI agents on permissions
Image: Michielbdejong (auto-discovered)

Run a company of people and AI agents on permissions instead of roles. https://noroles.com

Agents now write, build, sell and pay. Companies still run on titles, managers and approvals, so the work waits. NoRoles replaces the org chart with one open list: who can say yes to the few actions that can't be undone (money leaving, contracts, public words, personal data). Everything else, anyone just does. An agent acts with exactly its person's permissions, never more.

npx noroles init my-company

| MANIFESTO.md | eighteen principles: how we think and work | | SPEC.md | the model: permissions, mandates, rules, eight laws, and what the orchestrator must enforce | | npm/ | the noroles command line: start a company, ask for a yes, sign it, run agents with only the keys their mandate allows |

noroles open first-website       # the holders say yes to a mandate once
noroles ask --as me-agent --mandate first-website --permission money.spend \
  --summary "buy example.com for 1 year" --amount 12 --currency USD --to Namecheap
noroles yes <id>                 # a person, in a terminal, sees the exact action and signs
noroles do <id>                  # runs the approved command once, with only its own key
noroles run first-website --as me-agent -- claude
noroles mcp-config first-website --as me-agent > .mcp.json   # every tool call goes through NoRoles

See npm/README.md for what the code enforces today and what it does not yet.

Issues and pull requests are welcome. Every change to how approvals work needs a test in npm/test/laws.test.js that names the law or attack it covers.

MIT licensed.

── more in #ai-agents 4 stories · sorted by recency
── more on @noroles 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/noroles-run-a-compan…] indexed:0 read:1min 2026-09-28 · —