Guard Operator
Guard Operator is the optional privileged companion to the read-only Hass Guard agent. It requests Supervisor's manager role for narrowly typed, audited backup and app-management commands. It can create one full compressed backup, set the stale-backup threshold, and operate only Craftama Guard Connector; restore, delete, storage selection, and all other apps remain outside its local contract.
Its outbound WebSocket provides live presence and wakeups; the durable HTTPS queue still transports commands/results and remains the fallback when WSS is unavailable.
It defaults to manual boot and remote_control: false. The software switch rejects commands, but it cannot remove the manager token Home Assistant injects while the app is running. Stop or uninstall Operator to revoke that runtime permission.
Operator does not request the Home Assistant Core API, Docker socket, host network, admin role, full access, or an inbound port.
See the complete permission and command documentation.