Documentation
Permissions
Why root, what it reads, and the short list of what it may change.
Install and runtime
Installation needs root (sudo), systemd and the base tools (curl, openssl, sha256sum, base64). The agent runs as root: reading the authentication log, seeing every user's processes and changing firewall rules require it.
Reads
Authentication logs, /proc, the process table, listening sockets and connection tables (ss, conntrack), package databases, cron directories, systemd units, sshd -T, /etc/passwd, /etc/group and /etc/shadow (empty-password check only), web server and control panel configuration, web roots for integrity checks, and the Docker socket read-only when present.
May change, when the policy allows
- Firewall rules, through fail2ban, CrowdSec, CSF, firewalld or iptables.
- Service configuration, for an approved hardening fix (with a copy kept for undo).
- Package installs, through the system package manager, on approval.
- Service restarts, on approval.
- User account enable and disable, always on approval.
- Quarantine (mode 000 in place) and restore of a flagged file.
- Its own restart, upgrade and uninstall.
Never
- Deletes or moves your files.
- Rewrites application code.
- Opens an inbound port.
- Loads a kernel module or an eBPF program.
- Records keystrokes or shell sessions.
Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.