Roadmap item 4/10 · Workstream: Security · Risk: High · Approval required: Yes · Target milestone: M2 — Governed intake
Objective
Evaluate every proposed agent action against config/policies.yaml and the risk score, and route anything that needs approval to a human gate that costs the approver one step (per docs/human-in-the-loop-protocol.md), with the decision recorded as an audit event.
Non-goals
- A general RBAC system
- Approvals for actions outside this platform
- Auto-approving new action classes
Acceptance criteria
Dependencies
Risk
High — a policy bug either blocks all automation or silently allows destructive actions.
Test evidence required
- Table-driven tests for every rule in
config/policies.yaml plus unknown-action and protected-path cases
- Test that timeout and malformed approval responses resolve to deny
- Recorded dry-run of one gated action through approve and deny paths
Definition of done
Objective
Evaluate every proposed agent action against
config/policies.yamland the risk score, and route anything that needs approval to a human gate that costs the approver one step (perdocs/human-in-the-loop-protocol.md), with the decision recorded as an audit event.Non-goals
Acceptance criteria
allow/require_approval/denywith the matched rule and risk band (core/policy_engine.py,core/risk_scorer.py)require_approval(fail closed), neverallow.github/workflows/,config/,core/) always require approvalDependencies
Risk
High — a policy bug either blocks all automation or silently allows destructive actions.
Test evidence required
config/policies.yamlplus unknown-action and protected-path casesDefinition of done