{"slug": "noroles-run-a-company-of-people-and-ai-agents-on-permissions", "title": "NoRoles – run a company of people and AI agents on permissions", "summary": "NoRoles launched an MIT-licensed open-source tool that replaces corporate roles and titles with a permission list, letting AI agents act with exactly their person's permissions and requiring a human sign-off only for irreversible actions such as money leaving, contracts, public words, and personal data. The `noroles` command line, installed via `npx noroles init my-company`, supports commands including `noroles open`, `noroles ask`, `noroles yes`, `noroles do`, `noroles run`, and `noroles mcp-config`, and routes every MCP tool call through NoRoles. The project ships a MANIFESTO.md with eighteen principles and a SPEC.md defining permissions, mandates, rules, eight laws, and orchestrator enforcement, and requires every change to approval behavior to add a test in `npm/test/laws.test.js` naming the law or attack it covers.", "body_md": "**Run a company of people and AI agents on permissions instead of roles.** [https://noroles.com](https://noroles.com)\n\nAgents now write, build, sell and pay. Companies still run on titles, managers and approvals, so the work waits. NoRoles replaces the org chart with one open list: who can say yes to the few actions that can't be undone (money leaving, contracts, public words, personal data). Everything else, anyone just does. An agent acts with exactly its person's permissions, never more.\n\n```\nnpx noroles init my-company\n```\n\n| [`MANIFESTO.md`](https://github.com/noroles/NoRoles/blob/main/MANIFESTO.md) | eighteen principles: how we think and work | \n| [`SPEC.md`](https://github.com/noroles/NoRoles/blob/main/SPEC.md) | the model: permissions, mandates, rules, eight laws, and what the orchestrator must enforce | \n| [`npm/`](https://github.com/noroles/NoRoles/blob/main/npm) | the `noroles` command line: start a company, ask for a yes, sign it, run agents with only the keys their mandate allows | \n\n```\nnoroles open first-website       # the holders say yes to a mandate once\nnoroles ask --as me-agent --mandate first-website --permission money.spend \\\n  --summary \"buy example.com for 1 year\" --amount 12 --currency USD --to Namecheap\nnoroles yes <id>                 # a person, in a terminal, sees the exact action and signs\nnoroles do <id>                  # runs the approved command once, with only its own key\nnoroles run first-website --as me-agent -- claude\nnoroles mcp-config first-website --as me-agent > .mcp.json   # every tool call goes through NoRoles\n```\n\nSee [`npm/README.md`](https://github.com/noroles/NoRoles/blob/main/npm/README.md) for what the code enforces today and what it does not yet.\n\nIssues and pull requests are welcome. Every change to how approvals work needs a test in `npm/test/laws.test.js` that names the law or attack it covers.\n\nMIT licensed.", "url": "https://wpnews.pro/news/noroles-run-a-company-of-people-and-ai-agents-on-permissions", "canonical_source": "https://github.com/noroles/noroles", "published_at": "2026-09-28 17:34:47+00:00", "updated_at": "2026-09-28 17:49:53.032560+00:00", "lang": "en", "topics": ["ai-agents", "agent-protocols", "developer-tools", "ai-safety"], "entities": ["NoRoles", "noroles", "Namecheap", "Claude", "npm", "Model Context Protocol"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/noroles-run-a-company-of-people-and-ai-agents-on-permissions", "markdown": "https://wpnews.pro/news/noroles-run-a-company-of-people-and-ai-agents-on-permissions.md", "text": "https://wpnews.pro/news/noroles-run-a-company-of-people-and-ai-agents-on-permissions.txt", "jsonld": "https://wpnews.pro/news/noroles-run-a-company-of-people-and-ai-agents-on-permissions.jsonld"}}