Always-on access to every registered application and MCP capability for active owners, while authentication, tenant isolation, audit and infrastructure safety boundaries remain enforced.
God mode is derived from a freshly verified, active owner role in the database. There is no email allowlist, pilot membership or session toggle. A role downgrade, account deactivation or the infrastructure emergency control removes God mode on the next request.
Active owners can discover and execute registered capabilities across Finance, Marketing, Banners, publishing, media generation, administration and MCP integrations without application rollout, permission, budget or confirmation gates. Banner capabilities include creating an editable, unpublished 300×250 draft directly through MCP with transaction-bound idempotency and audit. Missing providers, bindings, secrets or unimplemented tools remain real operational failures.
God mode never bypasses authentication or session validation, exact active-owner authority, tenant, client and entity isolation, mandatory append-only audit, emergency disable, provider and secret requirements, database constraints or SSRF protection. It is broad application authority, not arbitrary security bypass.
Ordinary employees continue to receive role-scoped capabilities through evaluated department packs, pilot membership, release state, permissions, personal settings and confirmation controls. Owner God mode is reported separately so draft, failed, suspended and retired employee releases stay visible and truthful in governance reporting.