Skip to content

Add disabled Always-On action policy foundation - #521

Open
leprachuan wants to merge 1 commit into
mainfrom
codex/issue-520-autonomy-policy
Open

leprachuan wants to merge 1 commit into
mainfrom
codex/issue-520-autonomy-policy

Conversation

@leprachuan

@leprachuan leprachuan commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Always-On agents need scoped server-owned permissions before autonomous work can be enabled. This adds canonical action fingerprints, literal agent/operation/host/resource allow/ask/deny rules, deny precedence, atomic JSON persistence, and creation/revocation audit metadata. Unknown and opaque shell/python/browser/delegation actions still ask even with a matching allow rule. Defaults disabled; no execution paths or current chat behavior change.

Validation: 23 focused tests passed on dev 192.168.1.100, covering mismatched scope, path traversal/boundaries, fingerprint binding, corrupt schema, invalid feature flags, revocation, and failed atomic writes.

Tracks #519 and #520. The execution-surface map records SDK built-ins and runtime boundaries Stage 2 must enforce before enablement. Remaining: shared approvals and authorized APIs, execution wiring, inherited delegation constraints, symlink-safe adapters, process-safe policy coordination, and all three UI clients.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant