Repository navigation
feat(policy): govern agent tools from configured documents - #133
Merged
Merged
Conversation
Resolve agent policy and tenant with the shared flag, environment and config precedence before model setup or delegation. Preserve config-relative paths and report the actual policy source. Add six regression cases and update governance documentation and selected-test figures. This follow-up is based on contributor PR #131; the original contributor commit remains its parent.
Reject NaN, infinity and overflowing environment durations before bot startup, and reject NaN approval waits at the command gate. Positive fractional values and existing command budgets remain configurable. Update timing documentation and the selected-test figure. Fixes #135.
Shashankss1205
marked this pull request as ready for review
October 9, 2026 17:22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
grapharc agentpreviously built tool authority from CLI globs and ignored policy documents in configuration. Compile a selected document into the harness policy, combine it with flag restrictions using DENY > ASK > ALLOW, and route document approvals through the existing approval boundary. Document authority cannot be widened by an allow flag; policy-bearing runs refuse Claude Code delegation.Resolve policy and tenant from flags, environment and grapharc.toml, preserving config-relative paths and reporting the actual source, version, digest, tenant and audit path. Reject invalid setup before creating a workspace or model. Document-driven denials and approval outcomes reach the document audit; ordinary allowed calls are still only represented in the run trace.
This integrates @DhineshPonnarasan’s original commit from #131 and preserves its authorship and ancestry, together with the configuration correction. The branch includes the predecessor fixes in #132, #136 and #137 so their test-count updates do not conflict; merge after #137. The final diff against main narrows to the agent-policy changes once those predecessors land.
Validation: the six configuration regression cases failed against unmodified #131. The integrated policy/harness/CLI/documentation checks passed 381 tests with 1 skipped; ruff and diff checks are clean. Updated commit CI runs the full suite on Python 3.12/3.13/3.14, distribution checks and the live-test guard. Paid live tests remain excluded.
Closes #6. Includes #131.