## Context
`cx <subcommand> --help` currently mixes global flags with
command-specific flags under one `Options` section, which makes it
harder to see what applies to the command itself. This PR separates
inherited global options from per-command options in help output while
preserving the existing top-level domain-grouped command catalog.
## Linked Issues
AIAPP-1887 — inferred from the branch name.
## Design
The CLI continues to use Clap derive in `src/main.rs`. Global flags
remain on the top-level `Cli` struct with `global = true`, but each now
has `help_heading = "Global Options"` so Clap renders them separately on
subcommand help. The existing custom top-level help template keeps the
curated domain grouping and is styled to match Clap's automatic help
headings and command literals.
## Key Decisions
Clap does not provide a tag/label mechanism for grouping top-level
subcommands by domain, so the custom top-level command catalog stays in
place. Instead of replacing it with a flat generated `Commands:`
section, this PR styles the custom headings and command names with the
same ANSI styles Clap uses for generated help. The `(risky)` annotations
remain plain text so only the command literal is styled.
## Changes
- Separates command-local options from inherited global options in
subcommand help.
- Renames the top-level flag section from `Options` to `Global Options`.
- Applies Clap-like styling to custom top-level help headings and
command names.
- Updates the contributor help-template example to use `{usage-heading}`
and `Global Options`.
Original installed `cx logs --help` excerpt:
```text
Options:
-p, --profile <PROFILE>
Profile(s) to use. Repeat to fan out across multiple profiles simultaneously. Overrides the default profile set in config
--start <START>
Start time in ISO 8601 or relative format. e.g. "2024-01-01T00:00:00Z" or "now-1h"
--api-key <API_KEY>
Coralogix API key (overrides a single profile; incompatible with multiple --profile)
--end <END>
End time in ISO 8601 or relative format
--limit <LIMIT>
Maximum number of results
--region <REGION>
Coralogix region (overrides a single profile; incompatible with multiple --profile)
-o, --output <OUTPUT>
Output format: text, json, or agents. Overrides the default set in config
--tier <TIER>
Storage tier to search. Overrides the profile's default_tier setting. If neither is set, defaults to archive
--yes
Skip confirmation prompts for destructive operations
--read-only
Block all write operations. Useful for safe agent/automation access
```
New local `target/debug/cx logs --help` excerpt:
```text
Options:
--start <START>
Start time in ISO 8601 or relative format. e.g. "2024-01-01T00:00:00Z" or "now-1h"
--end <END>
End time in ISO 8601 or relative format
--limit <LIMIT>
Maximum number of results
--tier <TIER>
Storage tier to search. Overrides the profile's default_tier setting. If neither is set, defaults to archive
-h, --help
Print help (see a summary with '-h')
Global Options:
-p, --profile <PROFILE>
Profile(s) to use. Repeat to fan out across multiple profiles simultaneously. Overrides the default profile set in config
--api-key <API_KEY>
Coralogix API key (overrides a single profile; incompatible with multiple --profile)
--region <REGION>
Coralogix region (overrides a single profile; incompatible with multiple --profile)
-o, --output <OUTPUT>
Output format: text, json, or agents. Overrides the default set in config
--yes
Skip confirmation prompts for destructive operations
--read-only
Block all write operations. Useful for safe agent/automation access
```
## Testing
- `cargo fmt`
- `cargo run -- --help`
- `target/debug/cx --help`
- `target/debug/cx logs --help`
- `target/debug/cx dataprime query --help`
- `target/debug/cx metrics query-range --help`
- `target/debug/cx profiles add --help`
- `target/debug/cx --read-only profiles add --help`
- `env -u NO_COLOR CLICOLOR_FORCE=1 target/debug/cx --help | sed -n
'1,36l'`
- `git diff --check`
Automated tests were not added or run because this is a help-text
formatting change and manual validation was requested.
## Risks & Rollout
Low risk: parsing behavior is unchanged and all global flags remain
global. The main risk is terminal styling portability for the custom
top-level catalog; Clap/anstream strips ANSI styling when colors are
disabled or unsupported, matching the behavior of generated help.
Rollback is reverting this commit.
## Out of Scope / Follow-ups
N/A — this PR fully covers the requested help-output separation and
styling alignment.
AIAG-749
## Summary
The E2E test suite has been failing in CI since PR #51 (May 3) due to
two issues: the CI API key lacked scopes for newly added APIs, and
bypass mechanisms silently skipped failing tests. This PR fixes both
problems and removes commands with backend API bugs.
- **Remove `run_tolerant` bypass from E2E harness** - All tests now use
strict `run_ok`/`run_ok_json` and fail loudly on any error. No more
silent skips.
- **Fix `users search` stderr leak** - Rewrite SAML auth error in
`resolve_team_id()` so it doesn't contain "Authentication failed", which
was tripping the harness assertion.
- **Fix `olly ask` text output test** - Explicitly pass `-o text`
instead of relying on profile default (which may be `agents`).
- **Remove `cx quotas` and `cx iam saml` commands** - Backend REST API
returns Permission Denied regardless of key scopes. Deleted command
definitions, dispatch, E2E tests, unit tests, and all documentation
references. The `saml` API module is preserved since the `users` command
depends on `SamlApi` for team-ID resolution.
## Test plan
- [x] `cargo build` compiles
- [x] `cargo test` - all unit/integration tests pass
- [x] `cargo clippy` - clean
- [x] `cx --help` - no `quotas` command
- [x] `cx iam --help` - no `saml` subcommand
- [x] E2E suite: 80 passed, 0 failed (with updated API key)
- [x] No stale `quotas`/`saml` references in code or docs
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
## Summary
- **DataPrime validation guidelines**: Added a "Validating a DataPrime
query" section to `skills/shared/dataprime-reference.md` (synced to
cx-alerts, cx-create-dashboard, cx-telemetry-querying); clarified that
DataPrime verification uses a fixed `now-15m` window (not the
dashboard's `$RANGE`), and detailed pass/hard-fail/soft-fail semantics
including `keypath does not exist` handling
- **Rename `contributor/` → `contributing/`**: Renamed the directory for
consistency and updated all references across CLAUDE.md,
CONTRIBUTING.md, and `.claude/skills/add-skill/SKILL.md`
- **Skip CI for docs-only changes**: Added `paths-ignore` to build,
lint, and test workflows so PRs touching only `skills/`, `docs/`,
`contributing/`, or `*.md` files don't trigger Rust CI
---------
Co-authored-by: Niv Hertz <46317590+niv-hertz@users.noreply.github.com>