Skip to content

feat(policy): govern agent tools from configured documents - #133

Merged
Shashankss1205 merged 5 commits into
mainfrom
fix/agent-policy-config
Oct 9, 2026
Merged

Shashankss1205 merged 5 commits into
mainfrom
fix/agent-policy-config

Conversation

@Shashankss1205

@Shashankss1205 Shashankss1205 commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

grapharc agent previously built tool authority from CLI globs and ignored policy documents in configuration. Compile a selected document into the harness policy, combine it with flag restrictions using DENY > ASK > ALLOW, and route document approvals through the existing approval boundary. Document authority cannot be widened by an allow flag; policy-bearing runs refuse Claude Code delegation.

Resolve policy and tenant from flags, environment and grapharc.toml, preserving config-relative paths and reporting the actual source, version, digest, tenant and audit path. Reject invalid setup before creating a workspace or model. Document-driven denials and approval outcomes reach the document audit; ordinary allowed calls are still only represented in the run trace.

This integrates @DhineshPonnarasan’s original commit from #131 and preserves its authorship and ancestry, together with the configuration correction. The branch includes the predecessor fixes in #132, #136 and #137 so their test-count updates do not conflict; merge after #137. The final diff against main narrows to the agent-policy changes once those predecessors land.

Validation: the six configuration regression cases failed against unmodified #131. The integrated policy/harness/CLI/documentation checks passed 381 tests with 1 skipped; ruff and diff checks are clean. Updated commit CI runs the full suite on Python 3.12/3.13/3.14, distribution checks and the live-test guard. Paid live tests remain excluded.

Closes #6. Includes #131.

DhineshPonnarasan and others added 5 commits October 1, 2026 07:50
Resolve agent policy and tenant with the shared flag, environment and config precedence before model setup or delegation. Preserve config-relative paths and report the actual policy source. Add six regression cases and update governance documentation and selected-test figures.

This follow-up is based on contributor PR #131; the original contributor commit remains its parent.
Reject NaN, infinity and overflowing environment durations before bot startup, and reject NaN approval waits at the command gate. Positive fractional values and existing command budgets remain configurable. Update timing documentation and the selected-test figure.

Fixes #135.
@Shashankss1205 Shashankss1205 changed the title fix(cli): honor configured agent policy (follow-up to #131) feat(policy): govern agent tools from configured documents Oct 9, 2026
@Shashankss1205
Shashankss1205 changed the base branch from review/agent-policy-131 to main October 9, 2026 17:22
@Shashankss1205
Shashankss1205 marked this pull request as ready for review October 9, 2026 17:22
@Shashankss1205
Shashankss1205 merged commit 842a405 into main Oct 9, 2026
8 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

policy: grapharc agent cannot be governed by a policy document

2 participants