Access rules and posture, roster-first. Bare access lists each ruled endpoint's access entities — the subnets, nodes, and endpoints its rules name, grouped by type, each with its rule count (and, for a subnet or this machine, its mode). Name an endpoint to scope the roster to it. The granular rule list is viewable only per named ruled entity, through the drill-down flags. Rules are node-sovereign: viewing another node's rules means running this on that node. allow/revoke/open edit as before. Usage: spt.exe endpoint access [OPTIONS] [ENDPOINT] [COMMAND] Commands: allow Whitelist a subject for an endpoint (creates the restriction if absent) deny Refuse a subject for an endpoint. Same subject/surface flags as allow remove Remove a rule by restating it — the same flags that created it revoke Remove a node from an endpoint's whitelist. Never widens: revoking the last node leaves the endpoint locked down (all unsolicited refused) open Delete an endpoint's restriction entirely — back to default-open help Print this message or the help of the given subcommand(s) Arguments: [ENDPOINT] Scope the roster to one target endpoint Options: --endpoint-rules Drill down: the rules naming this sender endpoint --json Emit machine-readable JSON instead of the human view. Honored by the read/status commands (list, whoami, status, description, role, the *-list queries, how-to); action commands ignore it --node-rules Drill down: the rules naming this origin node (pubkey hex) --subnet-rules Drill down: the rules naming this subnet -h, --help Print help (see a summary with '-h') Control surfaces: MSG — direct messages (a grant binds the single sender) RC_VIEW — read-only terminal viewing (a grant admits the whole machine) RC_ATTACH — interactive terminal control (a grant admits the whole machine) DIGEST — cross-node digest pull (a grant admits the whole machine) WAKE — waking a resting endpoint (a grant admits the whole machine) SUSPEND — suspending a running endpoint (a grant admits the whole machine) XFER — file transfer (a grant admits the whole machine) SHELL_LINK — driving a linked shell (a grant admits the whole machine) DISCOVER — being found: resolve, advertise, and the resources blurb (a grant admits the whole machine) FORK — forking this endpoint, mind and all (a grant admits the whole machine) Access rules and posture, roster-first. Bare access lists each ruled endpoint's access entities — the subnets, nodes, and endpoints its rules name, grouped by type, each with its rule count (and, for a subnet or this machine, its mode). Name an endpoint to scope the roster to it. The granular rule list is viewable only per named ruled entity, through the drill-down flags. Rules are node-sovereign: viewing another node's rules means running this on that node. allow/revoke/open edit as before. Usage: spt.exe endpoint access [OPTIONS] [ENDPOINT] [COMMAND] Commands: allow Whitelist a subject for an endpoint (creates the restriction if absent) deny Refuse a subject for an endpoint. Same subject/surface flags as allow remove Remove a rule by restating it — the same flags that created it revoke Remove a node from an endpoint's whitelist. Never widens: revoking the last node leaves the endpoint locked down (all unsolicited refused) open Delete an endpoint's restriction entirely — back to default-open help Print this message or the help of the given subcommand(s) Arguments: [ENDPOINT] Scope the roster to one target endpoint Options: --endpoint-rules Drill down: the rules naming this sender endpoint --json Emit machine-readable JSON instead of the human view. Honored by the read/status commands (list, whoami, status, description, role, the *-list queries, how-to); action commands ignore it --node-rules Drill down: the rules naming this origin node (pubkey hex) --subnet-rules Drill down: the rules naming this subnet -h, --help Print help (see a summary with '-h') Control surfaces: MSG — direct messages (a grant binds the single sender) RC_VIEW — read-only terminal viewing (a grant admits the whole machine) RC_ATTACH — interactive terminal control (a grant admits the whole machine) DIGEST — cross-node digest pull (a grant admits the whole machine) WAKE — waking a resting endpoint (a grant admits the whole machine) SUSPEND — suspending a running endpoint (a grant admits the whole machine) XFER — file transfer (a grant admits the whole machine) SHELL_LINK — driving a linked shell (a grant admits the whole machine) DISCOVER — being found: resolve, advertise, and the resources blurb (a grant admits the whole machine) FORK — forking this endpoint, mind and all (a grant admits the whole machine)