Critical-risk tools in Coalesce Transform
10 of the 100 tools in Coalesce Transform are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
`cancel_run`DestructiveCancel a running job ⚠️
-
`delete_env_role`DestructiveRemove environment role from a user ⚠️
-
`delete_environment`DestructiveDelete an environment ⚠️
-
`delete_git_account`DestructiveDelete a git account ⚠️
-
`delete_project_role`DestructiveRemove project role from a user ⚠️
-
`delete_project`DestructiveDelete a project ⚠️
-
`delete_workspace_job`DestructiveDelete a job ⚠️
-
`delete_workspace_node`DestructiveDelete a node from a workspace ⚠️
-
`delete_workspace_subgraph`DestructiveDelete a subgraph (nodes are NOT deleted) ⚠️
-
`serialize_workspace_node_to_disk_yaml`DestructiveConvert a cloud workspace node to the on-disk `nodes/*.yml` shape coa reads (drop into a coa project for dry-run rendering)
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.