Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
A skill your agent uses when designing data schemas, implementing sharing workflows, or auditing access control in Jazz applications.
$ npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install garden-co/classic-jazz jazz-permissions-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/garden-co/classic-jazz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/jazz-permissions-security .claude/skills/jazz-permissions-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "jazz-permissions-security" agent skill from https://github.com/garden-co/classic-jazz/tree/main/.cursor/skills/jazz-permissions-security into .claude/skills/jazz-permissions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jazz-permissions-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/garden-co/classic-jazz/tree/main/.cursor/skills/jazz-permissions-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install garden-co/classic-jazz jazz-permissions-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garden-co/classic-jazz.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.cursor/skills/jazz-permissions-security .agents/skills/jazz-permissions-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "jazz-permissions-security" agent skill from https://github.com/garden-co/classic-jazz/tree/main/.cursor/skills/jazz-permissions-security into .agents/skills/jazz-permissions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jazz-permissions-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install garden-co/classic-jazz jazz-permissions-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garden-co/classic-jazz.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.cursor/skills/jazz-permissions-security .cursor/skills/jazz-permissions-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "jazz-permissions-security" agent skill from https://github.com/garden-co/classic-jazz/tree/main/.cursor/skills/jazz-permissions-security into .cursor/skills/jazz-permissions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jazz-permissions-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/garden-co/classic-jazz.git --path .cursor/skills/jazz-permissions-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install garden-co/classic-jazz jazz-permissions-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garden-co/classic-jazz.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.cursor/skills/jazz-permissions-security .gemini/skills/jazz-permissions-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "jazz-permissions-security" agent skill from https://github.com/garden-co/classic-jazz/tree/main/.cursor/skills/jazz-permissions-security into .gemini/skills/jazz-permissions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jazz-permissions-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install garden-co/classic-jazz jazz-permissions-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/garden-co/classic-jazz.git skills-src && mkdir -p .github/skills && cp -r skills-src/.cursor/skills/jazz-permissions-security .github/skills/jazz-permissions-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "jazz-permissions-security" agent skill from https://github.com/garden-co/classic-jazz/tree/main/.cursor/skills/jazz-permissions-security into .github/skills/jazz-permissions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jazz-permissions-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install garden-co/classic-jazz jazz-permissions-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garden-co/classic-jazz.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.cursor/skills/jazz-permissions-security .opencode/skills/jazz-permissions-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "jazz-permissions-security" agent skill from https://github.com/garden-co/classic-jazz/tree/main/.cursor/skills/jazz-permissions-security into .opencode/skills/jazz-permissions-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jazz-permissions-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
jazz-permissions-securityA skill your agent uses when designing data schemas, implementing sharing workflows, or auditing access control in Jazz applications.
Jazz Permissions Security is an agent skill from garden-co/classic-jazz. Use this skill when designing data schemas, implementing sharing workflows, or auditing access control in Jazz applications. It covers the hierarchy of Groups, Accounts, and CoValues, ensuring data is private by default and shared securely through cascading permissions and invitations.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: A new kind of database that's distributed across your frontend, containers, serverless functions and its own storage cloud. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4f90501. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and svelte).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
jazz.toolsgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Jazz Permissions Security loads about 2.9k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 849 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from garden-co/classic-jazz at commit 4f90501, republished under its MIT licence (© garden-co). 849 words, ~2,899 tokens.
.claude/skills/jazz-permissions-security/SKILL.md (or your agent's skills folder).jazz-schema-design skill)If a user asks "How do I share X with Y?" or "Why can't I access this?", this is usually a Group Ownership issue.
Security is cryptographic and group-based. Every CoValue has an owner, and access is controlled through Groups. You add users to a Group, and that Group owns the CoValues.
Groups can be members of other groups, creating hierarchical permission structures with inherited roles.
Critical Rule: Just because List A contains a reference to Item B does NOT mean readers of List A can see Item B. Item B must be owned by a Group the reader has access to.
When creating CoValues without a specified owner, Jazz creates a new Group with the current account as the owner and sole admin member.
Code: MyMap.create({ ... })
To share data, you can either create a new Group and add members to it, or use an existing Group with multiple members.
Code: MyMap.create({ ... }, { owner: teamGroup })
Jazz uses fixed roles. You cannot create custom roles.
| Role | Capability | Best For |
|---|---|---|
| admin | Read, Write, Delete, Invite Members, Revoke Access, Change Roles | Team Owners, Creators |
| manager | Read, Write, Add/Remove readers/writers | Delegated management |
| writer | Read, Write | Collaborators, Team Members |
| reader | Read Only | Observers, Public Links |
| writeOnly | Write Only (Blind submissions) | Voting, Dropboxes |
All users can downgrade themselves or leave a group. Admins cannot be removed/downgraded except by themselves. Managers cannot remove/downgrade each other, but can remove/downgrade lower roles.
Note: Only admins can delete CoValues.
When assigning roles, you can add Accounts, Groups, or "everyone". When adding a group, the most permissive role wins for members with multiple entitlements.
const group = co.group().create();
const bob = await co.account().load(bobsId);
if (bob.$isLoaded) {
group.addMember(bob, "writer");
group.addMember(bob, "reader"); // Change role
group.removeMember(bob);
}const red = MyCoMap.create({ color: "red" });
const me = co.account().getMe();
if (me.canAdmin(red)) {
console.log("I can add users of any role");
} else if (me.canManage(red)) {
console.log("I can share value with others");
} else if (me.canWrite(red)) {
console.log("I can edit value");
} else if (me.canRead(red)) {
console.log("I can view value");
}
// Or get role directly
red.$jazz.owner.getRoleOf(me.$jazz.id); // "admin"Must pass the correct owner explicitly to ensure visibility.
// ❌ WRONG: Defaults to private, other members won't see it
const task = Task.create({ title: "Fix bug" });
project.tasks.push(task);
// ✅ RIGHT: Explicitly set owner
const task = Task.create(
{ title: "Fix bug" },
{ owner: project.$jazz.owner }
);
project.tasks.push(task);
// ✅ ALSO RIGHT: Create new group for independent permissions
const taskGroup = co.group().create();
taskGroup.addMember(project.$jazz.owner, 'writer');
const task = Task.create({ title: "Fix bug" }, { owner: taskGroup });Note: Inline creation (passing JSON) automatically handles group inheritance based on schema configuration (default is extendsContainer).
You MUST NOT use an Account as a CoValue owner.
React:
import { createInviteLink } from "jazz-tools/react";
const inviteLink = createInviteLink(organization, "writer");Svelte:
import { createInviteLink } from "jazz-tools/svelte";
const inviteLink = createInviteLink(organization, "writer");Generates URL: .../#/invite/[CoValue ID]/[inviteSecret]
React:
import { useAcceptInvite } from "jazz-tools/react";
useAcceptInvite({
invitedObjectSchema: Organization,
onAccept: async (organizationID) => {
const organization = await Organization.load(organizationID);
if (!organization.$isLoaded) throw new Error("Could not load");
me.root.organizations.$jazz.push(organization);
},
});Svelte:
<script lang="ts">
import { InviteListener } from "jazz-tools/svelte";
new InviteListener({
invitedObjectSchema: Organization,
onAccept: async (organizationID) => {
const organization = await Organization.load(organizationID);
if (!organization.$isLoaded) throw new Error("Could not load");
me.current.root.organizations.$jazz.push(organization);
},
});
</script>Programmatic:
await account.acceptInvite(organizationId, inviteSecret, Organization);const groupToInviteTo = Group.create();
const readerInvite = groupToInviteTo.$jazz.createInvite("reader");
await account.acceptInvite(group.$jazz.id, readerInvite);⚠️ Security: Invites do not expire and cannot be revoked. Never pass secrets as route parameters or query strings—only use fragment identifiers (hash in URL).
"Public" means "readable by anyone who knows the CoValue ID".
const group = Group.create();
group.addMember("everyone", "writer");
// Or use alias
group.makePublic("writer"); // Defaults to "reader"Use writeOnly role for request lists—users can submit requests but not read others.
const JoinRequest = co.map({
account: co.account(),
status: z.literal(["pending", "approved", "rejected"]),
});
function createRequestsToJoin() {
const requestsGroup = Group.create();
requestsGroup.addMember("everyone", "writeOnly");
return RequestsList.create([], requestsGroup);
}
async function sendJoinRequest(requestsList, account) {
const request = JoinRequest.create(
{ account, status: "pending" },
requestsList.$jazz.owner
);
requestsList.$jazz.push(request);
}
async function approveJoinRequest(joinRequest, targetGroup) {
const account = await co.account().load(joinRequest.$jazz.refs.account.id);
if (account.$isLoaded) {
targetGroup.addMember(account, "reader");
joinRequest.$jazz.set("status", "approved");
return true;
}
return false;
}Groups can be added as members of other groups, creating hierarchies.
const playlistGroup = Group.create();
const trackGroup = Group.create();
trackGroup.addMember(playlistGroup);When you add groups as members:
writeOnly)Warning: Deep nesting can cause performance issues.
Most Permissive Role Wins:
const addedGroup = Group.create();
addedGroup.addMember(bob, "reader");
const containingGroup = Group.create();
containingGroup.addMember(bob, "writer");
containingGroup.addMember(addedGroup);
// Bob stays writer (higher than inherited reader)const organizationGroup = Group.create();
organizationGroup.addMember(bob, "admin");
const billingGroup = Group.create();
billingGroup.addMember(organizationGroup, "reader");
// All org members get reader access to billing, regardless of org role// Remove group
containingGroup.removeMember(addedGroup);
// Get parent groups
containingGroup.getParentGroups(); // [addedGroup]Jazz automatically manages group ownership for nested CoValues:
const board = Board.create({
title: "My board",
columns: [["Task 1.1", "Task 1.2"], ["Task 2.1", "Task 2.2"]],
});Each column and task gets a new group that inherits from the referencing CoValue's owner.
const companyGroup = Group.create();
companyGroup.addMember(CEO, "admin");
const teamGroup = Group.create();
teamGroup.addMember(companyGroup);
teamGroup.addMember(teamLead, "admin");
teamGroup.addMember(developer, "writer");
const projectGroup = Group.create();
projectGroup.addMember(teamGroup);
projectGroup.addMember(client, "reader");$jazz.owner.red.$jazz.owner.getRoleOf(me.$jazz.id) to check the actual role. reader cannot write.writeOnly does not cascade.Ownership: Admin/manager modifies group membership, not CoValue ownership, which cannot be modified.
Permission inheritance: Nested CoValues inherit permissions from parent when created inline (behavior can be modified at the schema level).
Access control: Only members of a Group can access CoValues owned by that Group. References alone don't grant access.
Public access: makePublic() or addMember("everyone", "reader") makes Groups readable by anyone with the Group ID.
Invite links: createInviteLink() generates shareable URLs. Accept with useAcceptInvite() (React), InviteListener (Svelte) or account.acceptInvite().
Invite security: Never pass secrets as route parameters/query strings. Only use fragment identifiers.
Requesting access: writeOnly role on requests list allows non-members to submit join requests for admin review.
Cascading: Groups can be members of other groups. Roles inherit (admin, manager, writer, reader), but writeOnly doesn't. Most permissive role wins. Use getParentGroups() to inspect hierarchy.
When using an online reference via a skill, cite the specific URL to the user to build trust.
© garden-co, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .cursor/skills/jazz-permissions-security of garden-co/classic-jazz.
Open the folder on GitHubat commit 4f90501
Jazz Permissions Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Jazz Permissions Security this skillgarden-co/classic-jazz | 2.5k | — | ~2.9k | Automated safety check: Pass | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| K8s Security PoliciesCybereason-Public/owLSM | 280 | 12 repos | ~2k | Automated safety check: Pass | GPL-2.0 | |
| Payloadpayloadcms/payload | 45k | 5 repos | ~6.2k | Automated safety check: Pass | MIT | |
| Convex Setup Authspokvulcan/poker-planning | 115 | 8 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Cognitoitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Cybereason-Public/owLSM
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
payloadcms/payload
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
spokvulcan/poker-planning
Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
abpframework/abp
ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.
garden-co/classic-jazz
A skill your agent uses when optimizing Jazz applications for speed, responsiveness, and scalability.
garden-co/classic-jazz
A skill your agent uses when you need to write, review, or debug automated tests for applications built on the Jazz framework.
garden-co/classic-jazz
A skill your agent uses when building, debugging, or optimizing Jazz applications.
garden-co/classic-jazz
A skill your agent uses when writing or running performance benchmarks for Jazz packages.
garden-co/classic-jazz
Design and implement collaborative data schemas using the Jazz framework.
garden-co/classic-jazz
Generate changeset files for versioning and changelog management in this monorepo.
Categories
A skill your agent uses when designing data schemas, implementing sharing workflows, or auditing access control in Jazz applications. Jazz Permissions Security is an agent skill from garden-co/classic-jazz. Use this skill when designing data schemas, implementing sharing workflows, or auditing access control in Jazz applications.
Jazz Permissions Security fits situations like: designing data schemas; implementing sharing workflows; auditing access control in Jazz applications.
Run `npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a claude-code`. Or copy the skill folder (.cursor/skills/jazz-permissions-security in garden-co/classic-jazz) into .claude/skills/jazz-permissions-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a codex`. Or copy the skill folder (.cursor/skills/jazz-permissions-security in garden-co/classic-jazz) into .agents/skills/jazz-permissions-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garden-co/classic-jazz --skill jazz-permissions-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jazz-permissions-security, .gemini/skills/jazz-permissions-security, .github/skills/jazz-permissions-security and .opencode/skills/jazz-permissions-security in your project.
SKILL.md names no scripts, command-line tools or credentials: Jazz Permissions Security is instructions for the agent only.
SKILL.md names 2 domains. As links in the text: jazz.tools and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Jazz Permissions Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Jazz Permissions Security: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
garden-co (a GitHub organization) maintains it in garden-co/classic-jazz, which has 2,534 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on September 7, 2026.
Source: garden-co/classic-jazz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.