Fix production without access to production.

Caster turns the dangerous parts of running production into spells: named actions your team casts, each under a permission scoped to that action alone.

Checkout is down.

Take the ticket and bring it back without ever holding a credential.

Nobody holds a credential to production.

A spell carries only the verbs its action needs, and your own API server enforces that limit rather than trusting our code.

caster · demo · simulation

/revivify payments-db

✗ revivify is not granted to you for payments-db

payments-db runs in the platform namespace. Your revivify grant is scoped to storefront.

refused · out of your namespaces · logged

Read the full permission model, worst case first.

An agent is just another employee.

Give an agent /scry and it can read the logs of the services you named, and it can do nothing else at all.

caster · demo · simulation

oncall-agent: requesting the restart: /revivify cart-api

✗ oncall-agent doesn't hold /revivify

Its grant is /scry on storefront services. A restart needs a human holding the spell.

refused · cast by oncall-agent · logged

The failure this prevents has a name: excessive agency.

Run it in your own cluster.

Casteris pre-launch; leave an address and you'll hear first.

No spam. One email when it opens.

For the security review, read what stays in your cluster and what leaves.