Read your DigitalOcean account freely. Create and change resources as approved steps.
Connect DigitalOcean and Luumen can read your account the way you would: Droplets, firewalls, load balancers, volumes, databases, Kubernetes clusters, DNS domains, snapshots, and tags. Those answers come back right away. When a change is needed — a new firewall, a DNS record, another Droplet — Luumen shows the exact call first and waits for your approval. Authentication uses an API key.
48 tools: 21 read, 27 write. Reads answer instantly. Writes require approval by default. Everything is logged.
What a governed DigitalOcean run looks like inside Luumen.
Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Read actions answer immediately. Anything that writes — create custom image, create database cluster, create new block storage volume, create new domain, and more — is shown as a plan and requires approval by default, including the 11 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Every call to DigitalOcean — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.
Connect in minutes. Every action scoped, approved, and audited from day one.